Critical Update
According to Microsoft, a vulnerability in Outlook Express (and affecting Outlook as well) could allow an attacker to cause the mail client to run code of his or her choice on the affected users machine. Such code could take any desired action, limited only by the permissions of the recipient on the machine. Microsft has designated the security patch as a critical update.
Microsoft issued a security bulletin to alert users, stating, "If an attacker created a vCard containing specially malformed data and then emailed it to someone who uses an affected version of Outlook or Outlook Express, the data in the vCard could, when opened, could cause code of the attackers choice to run on the recipients machine. Such code could take any action the user himself could take, including adding, changing or deleting data, communicating with web sites, reformatting the disk drive, and other actions." Such action could also include placing a remote access trojan on the user's machine, or infecting it with a virus.
Affected versions are:
Further details on the patch may be found at:
Microsoft Outlook 98
Microsoft Outlook 2000
Microsoft Outlook Express 5.x
http://www.microsoft.com/technet/security/bulletin/MS01-012.asp
or it may be downloaded directly at:
http://www.microsoft.com/windows/ie/download/critical/q283908/default.asp

