|
Home > User Issues > Anti-virus > HTML Mail Updates
Several vulnerabilities in HTML mail make it possible for
malicious code or file attachments to launch when you preview a
message in some versions of Outlook, unless you have the latest
patches for Internet Explorer.
The lesson: Not only do you need to keep your
anti-virus software updated and scan any attachments
before opening them, but you should also stay current with
updates to Internet Explorer, whose components are used to
display HTML format mail messages in Outlook 98 and
later versions. For example, the latest update for IE neutralizes
the <IFRAME> tag used by Klez and other recent viruses. (NOTE:
This update will cause a change in the appearance of the Find pane
in Outlook 2000 and the Organize pane in Outlook 2000 and 2002. The
problem is that, for some reason, the update interferes with the
loading of the cascading style sheet used for those panes, which are
controlled by HTML code in an Outlook .dll. The benefit of the
greater security protection far outweighs this cosmetic annoyance.)
Microsoft
has issued a security bulletin,
MS02-021 E-mail Editor Flaw Could Lead to Script Execution on Reply
or Forward, with a patch to fix the security
vulnerability recently publicized by security consultant Georgi Guninski.
The reported exploit could allow malicious script to run when a user
replies to or forwards a message and is using WordMail as the
editor. Prerequisites for the patch: For Word 2002,
Office XP Service Pack 1. For Word 2000,
Office 2000 Service Release 1/1a.
See Protecting Microsoft Outlook against Viruses
for details on techniques for preventing viruses from
entering your system through Outlook or propagating to Outlook
address book entries.
Office
XP Service Pack 1 adds a new feature to Outlook 2002 -- the ability to display all incoming messages
(except those that are digitally signed or encrypted) in plain
text format. The original HTML or rich-text content is still
present in the message, but in both an open message and the
preview pane, the user sees only plain text.
OL2002 Users Can Read Nonsecure E-mail As Plain Text
explains this new feature and cautions that it can have an
effect on custom Outlook solutions.
Browser
Updates | Other HTML Mail Security Patches |
More Information
|