Microsoft's third bulletin of the day involves Outlook Express (OE), the free e-mail client bundled with Windows. MS04-013 outlines the problem, which affects versions 5.5 SP2, 6.0 SP1, and 6.0 on Server 2003. An attacker who builds malicious URLs could run HTML code in the Local Security zone of Internet Explorer, possibly resulting in a takeover of the system.
Because OE is included with Windows, all users of NT, 2000, XP, and Server 2003 were urged to apply the patch, even if the OE client isn't used as the default e-mail software on the system. An attacker would have to entice users to read a maliciously-crafted HTML e-mail message or use IE to surf to a malicious Web site to grab control of the PC, so workstations are at greatest risk, said Microsoft.
Security Bulletin MS04-014 is the only one of the quartet which wasn't rated "Critical." This "Important" vulnerability -- one step below Critical -- affects the Microsoft Jet Database Engine. A hacker skilled enough to craft a malicious database query could take complete control of a compromised PC
As is the norm for its critical vulnerability bulletins, Microsoft recommended that users immediately apply the patches associated with MS04-011, 012, and 013. Users can obtain updates by heading to Microsoft's Windows Update site.