From alerts@us-cert.gov Wed Mar 10 22:42:33 2004
From: US-CERT Alerts <alerts@us-cert.gov>
To: alerts@us-cert.gov
Date: Wed, 10 Mar 2004 21:21:49 -0500
Subject: US-CERT Cyber Security Alert SA04-070A -- Vulnerability in
    Microsoft Outlook 2002 


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Vulnerability in Microsoft Outlook 2002

   Original release date: March 10, 2004
   Last revised: --
   Source: US-CERT

Systems Affected

     Systems running Microsoft Office XP and Outlook 2002

Overview

     There is a vulnerability in Outlook 2002 that could allow attackers
     to take control of your computer.

Description

     By taking advantage of the way Outlook interprets email links, an
     attacker may be able to gain control of your computer.

     A technical description of these vulnerabilities is available from
     US-CERT in TA04-070A and from Microsoft in MS04-009.

Resolution

  Apply a patch

     Microsoft's Office Security Update for March 2004 links to the
     necessary patches.

       <http://www.microsoft.com/security/security_bulletins/20040309_off
       ice.asp>

References

     * US-CERT Technical Alert TA04-070A -
       <http://www.us-cert.gov/cas/techalerts/TA04-070A.html>
     * Microsoft's Office Security Update for March 2004 -
       <http://www.microsoft.com/security/security_bulletins/20040309_off
       ice.asp>
     * Microsoft Security Bulletin MS04-009 -
       <http://www.microsoft.com/technet/security/bulletin/ms04-009.mspx>
     _________________________________________________________________

   This document is available from

   <http://www.us-cert.gov/cas/alerts/SA04-070A.html>
     _________________________________________________________________

   Copyright 2004 Carnegie Mellon University.

   Terms of use, see <http://www.us-cert.gov/legal.html>

   Revision History

   March 10, 2004: Initial release

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQFAT8xpXlvNRxAkFWARAjPoAKC590q18f682ioznuHH3weDfcOUrACfS2u/
QROxIl92AAxtfo8z3C3Ccmc=
=3jgR
-----END PGP SIGNATURE-----
