CRITICAL – Buffer overflow in VML used by IE and Outlook
Summary
Threat Level: Critical Zero-Day Vulnerability
This threat is currently active and spreading in the wild. Most Windows-based computers, even if fully up-to-date with all the official Microsoft patches, are vulnerable right now unless certain actions are taken to protect yourself (see below).
What it does: Various websites, including advertising sites that generate advertisements appearing on trusted websites, become infected. These sites use a specific type of attack to slip through your computer’s security, leaving a big hole for your computer to be further attacked. Since some versions of Outlook and Outlook Express use Internet Explorer to display some types of e-mail, you can become infected just by displaying infected e-mails you receive.
Outlook Express/Outlook Won’t Save Passwords
![]()
Symptoms: Every time you open Outlook Express or Outlook you are asked to re-enter your password even though the Save Password box is checked (or grayed out).
Problem: Generally this is caused by a problem in the Registry with the Protected Storage System Provider key.
Resolution: Follow the steps below to fix this problem or visit Microsoft’s Knowledge Base article 29684 for an even more detailed information.
Exchange: OWA displays all mailboxes in a directory browsing format
![]()
Problem: After some unrelated changes are made to IIS 6.0, Exchange’s Outlook Web Access (OWA) acts differently. The normal login page is replaced by a login dialog box. After logging in, OWA displays all the mailboxes in a browseable directory format instead of the normal OWA content. You can select your mailbox and all folders display in the same manner. Charles Yang from Microsoft presented a solution that (mostly) worked for me in this situation.
look good