MS warns of script attacks for some Outlook users

29 Apr 2002 09:48


Outlook users running Word as their default email editor are vulnerable to harmful scripts sent by malicious users

On April 26, Microsoft released a new security bulletin, MS02-021, for anyone running Microsoft Word as the default email editor for Microsoft Outlook 2000 and 2002. (The Word option is enabled or disabled by clicking Tools > Options > Mail Format.) Users editing or creating email in rich text or HTML formats with the Word option could be vulnerable to harmful scripts sent from malicious users.

How it works
Users who only read their email via Word are not vulnerable; HTML email in Outlook uses Internet Explorer's security settings and will not run malicious scripts sent via email. However, users who reply or forward email using Word are at risk because Word does not have script-blocking capabilities.

Prevention
A patch is available from Microsoft. Outlook 2002 users who have enabled the "Read HTML email as plain text" feature in Office XP SP1 will not need to apply this patch.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

Story URL: http://news.zdnet.co.uk/internet/0,1000000097,2109279,00.htm

Copyright © 1995-2008 CNET Networks, Inc. All rights reserved
ZDNET is a registered service mark of CNET Networks, Inc. ZDNET Logo is a service mark of CNET Networks, Inc.