Weird MS Technical Services Email

S

Steve

I just received an email, supposedly from MS with a
randomly generated email address outside the MS domain
([email protected])

Am I being overly paranoid?

The body of the email follows. It implies that the update
is included and there was an attachment but outlook is
blocking it. I would think that MS would send this as
either a link or at least a zip file due to security
restrictions that are DEFAULT in Outlook. Is this an
oxymoron or what?


Microsoft Consumer

this is the latest version of security update,
the "September 2003, Cumulative Patch" update which
resolves all known security vulnerabilities affecting MS
Internet Explorer, MS Outlook and MS Outlook Express as
well as three newly discovered vulnerabilities. Install
now to protect your computer from these vulnerabilities,
the most serious of which could allow an attacker to run
executable on your computer. This update includes the
functionality of all previously released patches.


System requirements Windows 95/98/Me/2000/NT/XP
This update applies to MS Internet Explorer, version
4.01 and later
MS Outlook, version 8.00 and later
MS Outlook Express, version 4.01 and later
Recommendation Customers should install the patch at the
earliest opportunity.
How to install Run attached file. Choose Yes on
displayed dialog box.
How to use You don't need to do anything after
installing this item.

Microsoft Product Support Services and Knowledge Base
articles can be found on the Microsoft Technical Support
web site. For security-related information about
Microsoft products, please visit the Microsoft Security
Advisor web site, or Contact Us.

Thank you for using Microsoft products.

Please do not reply to this message. It was sent from an
unmonitored e-mail address and we are unable to respond
to any replies.

----------------------------------------------------------
----------------------
The names of the actual companies and products mentioned
herein are the trademarks of their respective owners.

Contact Us | Legal | TRUSTe
©2003 Microsoft Corporation. All rights reserved. Terms
of Use | Privacy Statement | Accessibility
 
K

Kathy [MSFT]

Hi,

I wanted to let you know that Microsoft does NOT will
email unsolicited security patches. Any mail you receive
that contains a file saying that it is a patch, or an
emai that says "click here" to receive the patch, etc.
did not come from Microsoft.

Rather, it appears you received the email resulting from
another computer (not yours) being invected by a mass
emailing worm. The two most widely-known are:

W32.Gibe_mm
http://securityresponse.symantec.com/avcenter/venc/data/w3
(e-mail address removed)

W32.Dumaru_mm
http://securityresponse.symantec.com/avcenter/venc/data/w3
(e-mail address removed)

Information on Bogus Microsoft Security Bulletin Emails
http://www.microsoft.com/technet/treeview/default.asp?
url=/technet/security/news/patch_hoax.asp

Any and all legitimate patches and updates are readily
available at http://windowsupdate.microsoft.com/. For
easy access, just start WindowsUpdate on your computer
and it will hook to the official Microsoft site to
provide you with access to patches and updates from
Microsoft.

Kathy Prince
Program Manager
Microsoft Support Lifecycle & Security

This posting is provided "AS IS" with no warranties, and
confers no rights.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

Cumlative Patch - Is this from MS? or Virus? 1
Multiple Infected EMails 4
Bogus MS email? Phishing? 1
Can I trust this Email? 2
MS email "Security Update" ?? 3
Real or Hoax? 1
email problems 1
spoof email? 3

Top