FYI…

- http://preview.tinyurl.com/33hq6d
March 23, 2007 ~ (Computerworld) "A just-disclosed bug in Windows Vista's built-in e-mail program can be used by hackers to run malicious code on a victimized PC, said a researcher today who two weeks ago touted an exploit-for-sale service. Microsoft acknowledged the report, and said it is investigating the vulnerability. Symantec's DeepSight network, which issued a warning about the vulnerability in Windows Mail early this morning, upped the threat rating from 6.8 to 7.5 in a follow-up alert after it confirmed that the bug was remote code exploitable. That means an attacker could introduce his or her own malware onto a compromised computer. Windows Mail is the successor to Outlook Express, the entry-level e-mail app that's been bundled with the operating system since the Windows 95 edition. By crafting an e-mail message with a link to a malicious file – one hosted on a remote Internet server, say – and duping the recipient to click on the link, an attacker could infect a Vista PC with software that steals identities or with a backdoor Trojan horse. In some cases, all that's required is that the user clicks on the link, said Symantec… Both Symantec and Microsoft urged users not to click links in unsolicited e-mail, while the former also recommended that users disable HTML within Windows Mail…"

> http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1658
Original release date: 3/24/2007
Source: US-CERT/NIST
"Overview: Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe)…"

:ph34r: