Search OutlookPower's 8,351 Outlook and all-things-email article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
THIS WEEK'S POWERTIP
Understanding Office XP Service Pack 3 and an important warning
By Diane Poremsky

Early last week Microsoft released Office XP Service Pack 3 along with security bulletin MS04-009. The exploit described in the security bulletin affects only Outlook 2002 SP2, so updating to SP3 takes care of one worry but may create more problems.

MS04-009 addresses a security vulnerability which exists within Outlook 2002 that could allow Internet Explorer to execute script code in the Local Machine zone on an affected system. To exploit this vulnerability, an attacker would have to host a malicious Web site that contained a Web page designed to exploit the vulnerability and then persuade a user to view the Web page.

Since users are only at risk when Outlook 2002 is configured as the default mail reader and when the "Outlook Today" home page is their default folder home page, you can disable Outlook Today by unchecking the option to show a folder homepage by default to fix this vulnerability.

Note that if an attacker exploited this vulnerability, the attacker would gain only the same privileges as the user. This means users whose accounts are configured to have few privileges on the system would be at less risk than users who operate with administrative privileges. This is why no one recommends logging on to administrator accounts for normal usage, even though it is more convenient.

Only Outlook 2002-SP2 is affected by this exploit, Outlook 98, 2000, and 2003 are not affected, however, anyone who doesn't use Outlook Today can disable it as a precaution. To disable Outlook Today, right click on the top level folder in the mailbox or personal folders. (It's the folder with the little house icon.) Choose Properties, then Home Page and remove the check from "Show home page by default for this folder".

As I mentioned earlier, updating to Outlook 2002 SP3 fixes the exploit but may create more problems. After installing Outlook 2002 SP3 you many see the "a program is trying to access...allow it for 1 minute" security warning.

This warning message is a result of Outlook 2002 SP3 adding additional properties to the list of those that are affected by the security features, properties which are blocked by Outlook 2003. Anti-spam add-ins, which read the message body as part of their anti-spam scanning, are a common cause, although others are affected by the changes as well. Many add-ins were updated following the release of Outlook 2003 and should work with SP3, but many others need re-engineered to work with Outlook 2002 SP3. Until the add-ins which cause this warning are updated, you'll need to either live with the warning or disable the add-in, as SP3 cannot be uninstalled. If you use a version of Windows that supports System Restore, you may be able use a restore point to remove SP3.


1  ·  2  ·  Next »
Other articles you might like
Home > Using Outlook > Migration & Setup > Updates > Office (5 articles)
   Office System 2003 has arrived
   An exciting week with SoBig, Blaster, and a new Office
   Office 2003 beta 2 refresh is out
Home > Using Outlook > Office (8 articles)
   Reformatting contacts before moving from Excel to Outlook
   Uninstalling Outlook and Office when they don't want to be uninstalled
   Moving contacts from Excel into Outlook
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent OutlookPower Articles
Can Outlook run when it's not running (and other mysteries)?
Exploring the dark side of social networks
How not to screw up when you send email
How to separate email accounts and still manage them
How to convert a PST file from an old format to a new format
Visnetic MailFlow can automate your organization's mail processing
How to make Outlook launch an app at a specific time?
OutlookPower News Center
Touch in Windows 7: Just for show?
Windows XP User: I'm No Thief
Windows 7 May Get Family Pack Discount
Microsoft Unleashes Five Service Packs for Its Enterprise Security Wares
Give an Old Desktop New Life
Europe won't pay more for Windows 7. Really!
IT wish list for SharePoint 2010: Keep it simple
>> Read all the news
More from the ZATZ journals
Computing Unplugged: Eight steps to successful and reliable home backups
David Gewirtz Online: CNN commentary and analysis
DominoPower: What to look for in a Domino-based document management solution
-- Advertisement --

ONLINE GROUP CALENDAR - FOR UP TO 100 OF YOUR CLOSEST FRIENDS
Stay organized and in control with 24/7 access to all of your important events, projects and files --whether you're at work, at home or on the road.

You can share your calendar, projects and files so everyone in your office is up to date. Plus, search your entire group to find times when everyone is available to meet, manage company resources and much more.

Organize your entire team for as low as $9.95 per year (and yes, that's where the decimal place is supposed to be!)

Tap here to get started right away.

-- Advertisement --

BECOME CONFIDENT AND PRODUCTIVE WITH OUTLOOK 2007 IN SIX WEEKS
You can become a confident, productive user of Outlook 2007 in six weeks.

The Introduction to Outlook 2007 online course makes it happen in just twelve short lessons. The course features an instructor-led online discussion forum, regular assignments and quizzes, printable class notes, and a certificate of completion.

Learn more, then register today, at http://www.ed2go.com/courses/io7.
ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
The Power Magazine for Microsoft Outlook and Exchange Users at OutlookPower.com
Copyright © 1998-2009, ZATZ Publishing. All rights reserved worldwide.
Outlook is a trademark of Microsoft Corporation.
Editor's Login