Vulnerable Systems:
* Microsoft Outlook 2002 SP3
* Microsoft Outlook 2003 SP3
* Microsoft Outlook 2007 SP2
The vulnerability is caused by an integer underflow error when parsing certain content and can be exploited to cause a heap-based buffer overflow via e.g. a specially crafted e-mail message.
Successful exploitation may allow execution of arbitrary code, but requires that Outlook is connected to an Exchange server with Online Mode (not default setting for Outlook 2003 and 2007).
Patch Availability:
Apply patches provided by MS10-064.