In Outlook Express, Microsoft Word (or Microsoft Excel)
can be automatically run from an Email message. The document to be editted
by Word can supplied by a remote Web server or FTP server. There can be
a bad security hole here if you have turned off the warning in Word about
automatically running macros when a document is loaded. If this warning has
been turned off, the Web server can download to Word a document that is infected
with a macro virus and your machine becomes infected also.
Netscape Messenger can also auto-launch Word from an Email message, but
it puts up a security warning first which allows you to stop Word from running.
This same security hole exists in Eudora 4, but was eliminated in Eudora 4.1.
The demo below shows how Word can be started up from an HTML pahe. The demo loads
a harmless test file.