A recent critical vulnerability has been identified in Windows Outlook Express, Windows Mail and Windows Live Mail. This security issue can allow remote code execution if the users visits a malicious e-mail server. The attacker can gain the same privileges of the computer as the user has.The security update addresses the vulnerability by correctly validating e-mail server responses.Patches have been released.
source:
http://www.theregister.co.uk/2010/05/12/may_patch_tuesday/
http://www.microsoft.com/technet/security/Bulletin/MS10-030.mspx
