From the WinAmp web site:
A vulnerability has been reported in Winamp, which can be exploited by malicious people to compromise a user/’s system.
The problem is caused due to insufficient restrictions on Winamp skin zip files (.wsz). This can e.g. be exploited by a malicious website using a specially crafted Winamp skin to place and execute arbitrary programs. With Internet Explorer this can be done without user interaction.
Naturally, the problem is worsened by using IE. This vulnerability apparently does not affect version 2.x of Winamp. (Yay!)
Found via Neil’s World.