• Outlook User
  • New Outlook app
  • Outlook.com
  • Outlook Mac
  • Outlook & iCloud
  • Developer
  • Microsoft 365 Admin
    • Common Problems
    • Microsoft 365
    • Outlook BCM
    • Utilities & Addins

Outlook and the latest RTF Exploits

Slipstick Systems

› Outlook › Outlook and the latest RTF Exploits

Last reviewed on April 23, 2021     No Comments

Earlier this week, Microsoft released Security Advisory (2953095): Vulnerability in Microsoft Word Could Allow Remote Code Execution

The problem: when Microsoft Word parses specially crafted RTF-formatted data, it can cause system memory to become corrupted and an attacker could execute arbitrary code as a result.

This vulnerability could be exploited through Microsoft Outlook only when Microsoft Word is the email viewer, and Word is the only email editor/viewer in Outlook 2007, 2010, and 2013. An attacker could also exploit the vulnerability by sending a specially crafted RTF email message to the user.

The recommended solutions are to disable RTF document support in Word; if enabled, disable the option to open RTF messages in Word if using older versions of Outlook; and enable “read as plain text” in Outlook.

To check and disable RTF settings in Outlook 2003 and older: Open Tools, Options, Mail Format tab. The option to Use Microsoft Office Word to read Rich Text e-mail messages should be unchecked.

Disable Word for reading RTF email

While you are unable to disable Word as the email reader in Outlook 2007, 2010, and 2013, you can configure Outlook to read all mail using plain text format by default. Or use a macro to convert RTF formatted messages to plain text format.

In Outlook 2010/2013, the Read all standard mail in plain text setting is in File, Options, Trust Center, Email Security.

Read as plain text setting

While the options above will protect users from RTF formatted messages, they would still be able to open RTF attachments. To prevent this from happening in Office 2010 or 2013, check Word’s options for Protected View and File Block Settings. In Word’s File, Options, Trust Center, select Protected View. Is Protected View enabled for files originating from the Internet and for Outlook Attachments?

Protected View Settings

Select File Block Settings and adjust the settings so RTF messages are opened in Protected View or blocked from opening.

Don't open RTF

File Block Settings and Protected View can be controlled using Group Policy for Office 2007, 2010, and 2013. Sites still using Office 2003 can set a registry key to block RTF documents. Note that all current security updates must be installed for the key to work.

Outlook 2003 registry key
HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Word\Security\FileOpenBlock
DWORD: RtfFiles
Value: 1

If you don't want to edit the registry yourself, I have a ready to use reg file here: RtfFiles - Outlook 2003

With File Block set, users who have not configured a special exempt directory or have not moved files to a trusted location will be unable to open RTF files. For more information about the impact of file block setting in Microsoft Office software, see Error message in Office when a file is blocked by registry policy settings.

More Information

Macro to Convert RTF Messages to Plain Text Format
Read Outlook Messages using Plain Text
Microsoft security advisory: Vulnerability in Microsoft Word could allow remote code execution Includes a Mr FixIt to set the File Block Settings for users.

Outlook and the latest RTF Exploits was last modified: April 23rd, 2021 by Diane Poremsky

Related Posts:

  • Read Outlook Messages using Plain Text
  • BadWinMail Exploit
  • Block Macros in Office 2013/2016
  • Disable Protected View for Outlook Attachments

About Diane Poremsky

A Microsoft Outlook Most Valuable Professional (MVP) since 1999, Diane is the author of several books, including Outlook 2013 Absolute Beginners Book. She also created video training CDs and online training classes for Microsoft Outlook. You can find her helping people online in Outlook Forums as well as in the Microsoft Answers and TechNet forums.

Subscribe
Notify of
0 Comments
newest
oldest most voted
Inline Feedbacks
View all comments

Visit Slipstick Forums.
What's New at Slipstick.com

Latest EMO: Vol. 30 Issue 32

Subscribe to Exchange Messaging Outlook






Support Services

Do you need help setting up Outlook, moving your email to a new computer, migrating or configuring Office 365, or just need some one-on-one assistance?

Our Sponsors

CompanionLink
ReliefJet
  • Popular
  • Latest
  • Week Month All
  • Jetpack plugin with Stats module needs to be enabled.
  • Move Deleted Items to Another Folder Automatically
  • Open Outlook Templates using PowerShell
  • Count and List Folders in Classic Outlook
  • Google Workspace and Outlook with POP Mail
  • Import EML Files into New Outlook
  • Opening PST files in New Outlook
  • New Outlook: Show To, CC, BCC in Replies
  • Insert Word Document into Email using VBA
  • Delete Empty Folders using PowerShell
  • Warn Before Deleting a Contact
Ajax spinner

Recent Bugs List

Microsoft keeps a running list of issues affecting recently released updates at Fixes or workarounds for recent issues in classic Outlook (Windows).

For new Outlook for Windows: Fixes or workarounds for recent issues in new Outlook for Windows .

Outlook for Mac Recent issues: Fixes or workarounds for recent issues in Outlook for Mac

Outlook.com Recent issues: Fixes or workarounds for recent issues on Outlook.com

Office Update History

Update history for supported Office versions is at Update history for Office

Outlook Suggestions and Feedback

Outlook Feedback covers Outlook as an email client, including Outlook Android, iOS, Mac, and Windows clients, as well as the browser extension (PWA) and Outlook on the web.

Outlook (new) Feedback. Use this for feedback and suggestions for Outlook (new).

Use Outlook.com Feedback for suggestions or feedback about Outlook.com accounts.

Other Microsoft 365 applications and services




New Outlook Articles

Move Deleted Items to Another Folder Automatically

Open Outlook Templates using PowerShell

Count and List Folders in Classic Outlook

Google Workspace and Outlook with POP Mail

Import EML Files into New Outlook

Opening PST files in New Outlook

New Outlook: Show To, CC, BCC in Replies

Insert Word Document into Email using VBA

Delete Empty Folders using PowerShell

Warn Before Deleting a Contact

Newest Code Samples

Open Outlook Templates using PowerShell

Count and List Folders in Classic Outlook

Insert Word Document into Email using VBA

Warn Before Deleting a Contact

Use PowerShell to Delete Attachments

Remove RE:, FWD:, and Other Prefixes from Subject Line

Change the Mailing Address Using PowerShell

Categorize @Mentioned Messages

Send an Email When You Open Outlook

Delete Old Calendar Events using VBA

Repair PST

Convert an OST to PST

Repair damaged PST file

Repair large PST File

Remove password from PST

Merge Two Data Files

Sync & Share Outlook Data

  • Share Calendar & Contacts
  • Synchronize two computers
  • Sync Calendar and Contacts Using Outlook.com
  • Sync Outlook & Android Devices
  • Sync Google Calendar with Outlook
  • Access Folders in Other Users Mailboxes

Diane Poremsky [Outlook MVP]

Make a donation

Mail Tools

Sending and Retrieval Tools

Mass Mail Tools

Compose Tools

Duplicate Remover Tools

Mail Tools for Outlook

Online Services

Calendar Tools

Schedule Management

Calendar Printing Tools

Calendar Reminder Tools

Calendar Dates & Data

Time and Billing Tools

Meeting Productivity Tools

Duplicate Remover Tools

Productivity

Productivity Tools

Automatic Message Processing Tools

Special Function Automatic Processing Tools

Housekeeping and Message Management

Task Tools

Project and Business Management Tools

Choosing the Folder to Save a Sent Message In

Run Rules on messages after reading

Help & Suggestions

Submit Outlook Feature Requests

Slipstick Support Services

Buy Microsoft 365 Office Software and Services

Visit Slipstick Forums.

What's New at Slipstick.com

Home | Outlook User | Exchange Administrator | Office 365 | Outlook.com | Outlook Developer
Outlook for Mac | Common Problems | Utilities & Addins | Tutorials
Outlook & iCloud Issues | Outlook Apps
EMO Archives | About Slipstick | Slipstick Forums
Submit New or Updated Outlook and Exchange Server Utilities

Send comments using our Feedback page
Copyright © 2025 Slipstick Systems. All rights reserved.
Slipstick Systems is not affiliated with Microsoft Corporation.

:wpds_smile::wpds_grin::wpds_wink::wpds_mrgreen::wpds_neutral::wpds_twisted::wpds_arrow::wpds_shock::wpds_unamused::wpds_cool::wpds_evil::wpds_oops::wpds_razz::wpds_roll::wpds_cry::wpds_eek::wpds_lol::wpds_mad::wpds_sad::wpds_exclamation::wpds_question::wpds_idea::wpds_hmm::wpds_beg::wpds_whew::wpds_chuckle::wpds_silly::wpds_envy::wpds_shutmouth:
wpDiscuz

Sign up for Exchange Messaging Outlook

Our weekly Outlook & Exchange newsletter (bi-weekly during the summer)






Please note: If you subscribed to Exchange Messaging Outlook before August 2019, please re-subscribe.

Never see this message again.

You are going to send email to

Move Comment