An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user\'s mailbox via a message attachment that contains HTML code, which is executed automatically.