This afternoon, the MSRC posted a security advisory describing a newly-disclosed vulnerability in the IIS FTP service that could potentially grant remote code execution to untrusted users. You can find the advisory here.
Vulnerability summary
The vulnerability is a stack overflow in the FTP service when listing a long, specially-crafted directory name.