
The advisory labelled the bug "medium risk" because it requires user interaction to be exploited.
According to a National Vulnerability Database summary, The vulnerability exists because Windows Mail might allow remote attackers to execute certain programs via a link to a local file or UNC (universal naming convention) share path name in which there is a directory with the same base name as an executable program at the same level.
UNC is a filename format used to indicate the location of directories or resources to be accessed.
A Microsoft spokesman said the software giant was investigating, but not aware of any attacks exploiting the flaw.
Vista deployment rates are still low within the enteprise, with most analysts expecting the roll-over to come in the next 18 to 24 months.