Microsoft does not email updates. Period.
Are you absolutely sure?
There are several sender addresses, but all very similar.
I've already deleted the latest batch, but I had saved one
in my inbox in case I could use it to figure out who to
contact. The sender address is:
"MS Corporation Security Assistance"
<
[email protected]>
And the recipient address is:
"Commercial User" <
[email protected]>
It's a very convincing looking email. Here is some of the
text:
-------------------------------------------------
Microsoft User
this is the latest version of security update,
the "September 2003, Cumulative Patch" update which
resolves all known security vulnerabilities affecting MS
Internet Explorer, MS Outlook and MS Outlook Express as
well as three new vulnerabilities. Install now to continue
keeping your computer secure from these vulnerabilities,
the most serious of which could allow an malicious user to
run code on your computer. This update includes the
functionality of all previously released patches.
System requirements Windows 95/98/Me/2000/NT/XP
This update applies to MS Internet Explorer, version
4.01 and later
MS Outlook, version 8.00 and later
MS Outlook Express, version 4.01 and later
Recommendation Customers should install the patch at the
earliest opportunity.
How to install Run attached file. Choose Yes on displayed
dialog box.
How to use You don't need to do anything after installing
this item.
Microsoft Product Support Services and Knowledge Base
articles can be found on the Microsoft Technical Support
web site. For security-related information about Microsoft
products, please visit the Microsoft Security Advisor web
site, or Contact Us.
Thank you for using Microsoft products.
Please do not reply to this message. It was sent from an
unmonitored e-mail address and we are unable to respond to
any replies.
The names of the actual companies and products mentioned
herein are the trademarks of their respective owners.
Contact Us | Legal | TRUSTe
©2003 Microsoft Corporation. All rights reserved. Terms
of Use | Privacy Statement | Accessibility
--------------------------------------------------
The contact link goes to:
http://register.microsoft.com/contactus30/contactus.asp?
domain=generic
The legal link goes to:
http://www.microsoft.com/legal/
The TRUSTe link goes to:
https://www.truste.org/validate.php?invnum=605&fromcgi=1
This all seems very offical to me, not like some spammer
or anything.