Two high risk flaws in Microsoft's Internet Explorer and Outlook have been reported by security vulnerability specialists eEye Digital Security.
The security holes could let an attacker take over a system with 'minimal user interaction', the company said in two security alerts posted on its web site.
The software holes affect the default installations of Internet Explorer and Outlook running on Windows NT 4.0, Windows 2000, Windows XP or Windows Server 2003.
A spokeswoman for Microsoft confirmed that the company has been notified about the flaws.
"At this time, Microsoft is not aware of any malicious attacks attempting to exploit the reported vulnerabilities, and there is no customer impact based on this issue," she said.
"Depending on the severity of the flaw, Microsoft will issue a fix through a service pack, one of the company's monthly patches or and out-of-cycle security update."
Microsoft usually distributes fixes through its monthly patches on the second Tuesday of the month. The company will release an out-of-cycle update in case of an emergency.
This has happened three times since it adopted the monthly patching cycle in October 2003. All three patches targeted critical flaws in Internet Explorer.
Australian government to require technology and communications companies to provide access to messages
New bill avoids demanding 'backdoors' in encryption, but includes measures to compel companies to provide access to encrypted communications
Indonesian overclocker Ivan Cupa (with the aid of a lot of liquid nitrogen) achieves record overclock on AMD's latest Threadripper
Ssupermassive black hole is so big it corresponds to four per cent of the galaxy's total mass
Imminent attack will target a single bank with cloned cards used to fraudulently withdraw millions over one weekend