Search OutlookPower's 8,981 Outlook and all-things-email article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
THIS WEEK'S POWERTIP
Understanding Office XP Service Pack 3 and an important warning
By Diane Poremsky

Early last week Microsoft released Office XP Service Pack 3 along with security bulletin MS04-009. The exploit described in the security bulletin affects only Outlook 2002 SP2, so updating to SP3 takes care of one worry but may create more problems.

MS04-009 addresses a security vulnerability which exists within Outlook 2002 that could allow Internet Explorer to execute script code in the Local Machine zone on an affected system. To exploit this vulnerability, an attacker would have to host a malicious Web site that contained a Web page designed to exploit the vulnerability and then persuade a user to view the Web page.

Since users are only at risk when Outlook 2002 is configured as the default mail reader and when the "Outlook Today" home page is their default folder home page, you can disable Outlook Today by unchecking the option to show a folder homepage by default to fix this vulnerability.

Note that if an attacker exploited this vulnerability, the attacker would gain only the same privileges as the user. This means users whose accounts are configured to have few privileges on the system would be at less risk than users who operate with administrative privileges. This is why no one recommends logging on to administrator accounts for normal usage, even though it is more convenient.

Only Outlook 2002-SP2 is affected by this exploit, Outlook 98, 2000, and 2003 are not affected, however, anyone who doesn't use Outlook Today can disable it as a precaution. To disable Outlook Today, right click on the top level folder in the mailbox or personal folders. (It's the folder with the little house icon.) Choose Properties, then Home Page and remove the check from "Show home page by default for this folder".

As I mentioned earlier, updating to Outlook 2002 SP3 fixes the exploit but may create more problems. After installing Outlook 2002 SP3 you many see the "a program is trying to access...allow it for 1 minute" security warning.

This warning message is a result of Outlook 2002 SP3 adding additional properties to the list of those that are affected by the security features, properties which are blocked by Outlook 2003. Anti-spam add-ins, which read the message body as part of their anti-spam scanning, are a common cause, although others are affected by the changes as well. Many add-ins were updated following the release of Outlook 2003 and should work with SP3, but many others need re-engineered to work with Outlook 2002 SP3. Until the add-ins which cause this warning are updated, you'll need to either live with the warning or disable the add-in, as SP3 cannot be uninstalled. If you use a version of Windows that supports System Restore, you may be able use a restore point to remove SP3.


1  ·  2  ·  Next »
Other articles you might like
Home > Using Outlook > Migration & Setup > Updates > Office (5 articles)
   Office System 2003 has arrived
   An exciting week with SoBig, Blaster, and a new Office
   Office 2003 beta 2 refresh is out
Home > Using Outlook > Office (8 articles)
   Reformatting contacts before moving from Excel to Outlook
   Uninstalling Outlook and Office when they don't want to be uninstalled
   Moving contacts from Excel into Outlook
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent OutlookPower Articles
Running auto-respond rules when Outlook is closed
Running rules when Outlook is closed
Disappearing text that's not supposed to disappear
What to do when Outlook complains about a program you know you uninstalled
Nothing says new year better than emails from crazy people
Say goodbye to the Uh-Ohs. Long live the Tens.
How to have a clean inbox in 2010
OutlookPower News Center
EML to PST Converter - Conversion of Email Formats to Outlook
Windows 2000, XP SP2, Vista RTM support nears end
Windows 7 Just Being Honest About Battery Life
Remo Software Launches Data Recovery Software
US scientists get free cloud on-ramp
Leaky anti-virus defences letting malware through
Patch Tuesday Release Will Tie Microsoft's Record
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad: Apple's latest heartbreaker
David Gewirtz Online: CNN commentary and analysis
DominoPower: Lotusphere 2010: mobility and collaboration
-- Advertisement --

Write for OutlookPower today!
Share your experience and expertise with other Outlook and Exchange users, administrators, and developers. OutlookPower Magazine has grown nicely and now has new opportunities for contributing authors and editors.

Write about something you're an expert on and get your name in lights.

For Writers' Guidelines and to discuss topics, contact Staff Editor Steve Niles. This is your opportunity to shine in front of your peers, your clients, and other readers.

Click for more info!

-- Advertisement --

Five Email Mistakes You Should Avoid
Have you ever made any of these mistakes?

  • Forgotten to send an attachment you promised in a message
  • Replied-to-all, annoying everyone
  • Forgotten to Reply-to-All, annoying everyone
  • Sent emails using the wrong email account
  • Said something you oh-so-knew-better than to say

Send Guard can keep you looking good by saving you from yourself.

Tap here to download a fully-functional 30-day trial.

ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
The Power Magazine for Microsoft Outlook and Exchange Users at OutlookPower.com
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Outlook is a trademark of Microsoft Corporation.
Editor's Login