Microsoft released a security notice on March 1, 2010, warning Internet Explorer users that pressing F1 in IE can run malicious VBScript code and infect the system with Malware.
Until MS releases a fix via Windows Update, users are cautioned not to press F1 in their browser.
Here’s a potential example of how a user might be tricked into pressing F1 and running bad code on their computer:
I can imagine Grandma sitting in front of a page that says, “Your computer’s LHC has encountered fatal hard drive saturation. Press F1 for more information.”
For more details on this subject, check out the article on Tech Republic.