Search OutlookPower's 9,596 Outlook and all-things-email article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
THIS WEEK'S POWERTIP
Understanding Office XP Service Pack 3 and an important warning
By Diane Poremsky

Early last week Microsoft released Office XP Service Pack 3 along with security bulletin MS04-009. The exploit described in the security bulletin affects only Outlook 2002 SP2, so updating to SP3 takes care of one worry but may create more problems.

MS04-009 addresses a security vulnerability which exists within Outlook 2002 that could allow Internet Explorer to execute script code in the Local Machine zone on an affected system. To exploit this vulnerability, an attacker would have to host a malicious Web site that contained a Web page designed to exploit the vulnerability and then persuade a user to view the Web page.

Since users are only at risk when Outlook 2002 is configured as the default mail reader and when the "Outlook Today" home page is their default folder home page, you can disable Outlook Today by unchecking the option to show a folder homepage by default to fix this vulnerability.

Note that if an attacker exploited this vulnerability, the attacker would gain only the same privileges as the user. This means users whose accounts are configured to have few privileges on the system would be at less risk than users who operate with administrative privileges. This is why no one recommends logging on to administrator accounts for normal usage, even though it is more convenient.

Only Outlook 2002-SP2 is affected by this exploit, Outlook 98, 2000, and 2003 are not affected, however, anyone who doesn't use Outlook Today can disable it as a precaution. To disable Outlook Today, right click on the top level folder in the mailbox or personal folders. (It's the folder with the little house icon.) Choose Properties, then Home Page and remove the check from "Show home page by default for this folder".

As I mentioned earlier, updating to Outlook 2002 SP3 fixes the exploit but may create more problems. After installing Outlook 2002 SP3 you many see the "a program is trying to access...allow it for 1 minute" security warning.

This warning message is a result of Outlook 2002 SP3 adding additional properties to the list of those that are affected by the security features, properties which are blocked by Outlook 2003. Anti-spam add-ins, which read the message body as part of their anti-spam scanning, are a common cause, although others are affected by the changes as well. Many add-ins were updated following the release of Outlook 2003 and should work with SP3, but many others need re-engineered to work with Outlook 2002 SP3. Until the add-ins which cause this warning are updated, you'll need to either live with the warning or disable the add-in, as SP3 cannot be uninstalled. If you use a version of Windows that supports System Restore, you may be able use a restore point to remove SP3.


1  ·  2  ·  Next »
Other articles you might like
Home > Using Outlook > Migration & Setup > Updates > Office (5 articles)
   Office System 2003 has arrived
   An exciting week with SoBig, Blaster, and a new Office
   Office 2003 beta 2 refresh is out
Home > Using Outlook > Office (8 articles)
   Reformatting contacts before moving from Excel to Outlook
   Uninstalling Outlook and Office when they don't want to be uninstalled
   Moving contacts from Excel into Outlook
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent OutlookPower Articles
The strange case of Outlook losing notes and requiring passwords
Why I'm choosing to stick with Outlook 2007
Three ways to avoid email distraction and take back control of your time
Twenty ways to use email to commit career suicide
The two most motivational words in the English language
Diagnosing corrupted email headers
Email offenders
OutlookPower News Center
New Filing Assistant from Allometa
Dropbox bridges gaps in Microsoft's mobile sync
SmartBear Software Releases AQtime 7.0 Pro
6 Super Wi-Fi Tools for Windows
Microsoft Revives Windows 7 Family Pack Discount
Microsoft releases FixIt for critical flaw in 100 apps
M-Files Cloud Vault Easy, Hosted Document Management
>> Read all the news
More from the ZATZ journals
Computing Unplugged: Smartphone smarts for a mobile world
David Gewirtz Online: CNN commentary and analysis
DominoPower: It's time for Lotus to double-down on Linux and open source
-- Advertisement --

Write for OutlookPower today!
Share your experience and expertise with other Outlook and Exchange users, administrators, and developers. OutlookPower Magazine has grown nicely and now has new opportunities for contributing authors and editors.

Write about something you're an expert on and get your name in lights.

For Writers' Guidelines and to discuss topics, contact Staff Editor Steve Niles. This is your opportunity to shine in front of your peers, your clients, and other readers.

Click for more info!

-- Advertisement --

Personalized Emails Are Opened More
Create and send personalized, individually addressed copies of the same email to as many people as you want...using our easy Wizard Interface inside Outlook.

EmailMerge will help you make more sales. Send Personalized Business Emails, Holiday Greeting and Invites. EmailMerge will help you reach your customers, family, and friends in more personal and effective way. Supports Outlooks Contacts, Excel and Access files, delayed batch sending, multiple accounts and more within its easy to use Wizard interface.

Tap here to download a fully-functional 30-day trial.

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
The Power Magazine for Microsoft Outlook and Exchange Users at OutlookPower.com
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Outlook is a trademark of Microsoft Corporation.
Editor's Login