Microsoft last week warned IT administrators that critical vulnerabilities in code licensed from Oracle could give attackers access to Exchange Server 2007 and Exchange Server 2010 systems. The vulnerabilities are within the code that parses those attachments. Oracle patched the vulnerabilities in its “Oracle Outside In” code libraries as part of a massive update on July 17. Microsoft downplayed the threat, saying elsewhere that it was unaware of any active, in-the-wild exploits. Microsoft said it is working on an update, but gave no release timetable.”]

