OLEXP: Patch Available for MHTML E-mail Vulnerability (261253)



The information in this article applies to:

  • Microsoft Outlook Express 5.01 for Windows NT 4.0
  • Microsoft Outlook Express 5.0 for Windows NT 4.0
  • Microsoft Outlook Express 4.01 for Windows NT 4.0 SP 1
  • Microsoft Outlook Express 4.01 for Windows NT 4.0 SP 2
  • Microsoft Outlook Express 4.0 for Windows NT 4.0
  • Microsoft Outlook Express 5.01 for Windows 98 Second Edition
  • Microsoft Outlook Express 5.0 for Windows 98 Second Edition
  • Microsoft Outlook Express 5.01 for Windows 98
  • Microsoft Outlook Express 5.0 for Windows 98
  • Microsoft Outlook Express 4.01 for Windows 98 SP 1
  • Microsoft Outlook Express 4.01 for Windows 98 SP 2
  • Microsoft Outlook Express 5.01 for Windows 95
  • Microsoft Outlook Express 5.0 for Windows 95
  • Microsoft Outlook Express 4.01 for Windows 95 SP 2
  • Microsoft Outlook Express 4.0 for Windows 95
  • Microsoft Outlook 97
  • Microsoft Outlook 98
  • Microsoft Outlook 2000

This article was previously published under Q261253
For information about the differences between Microsoft Outlook Express and Microsoft Outlook e-mail clients, click the following article number to view the article in the Microsoft Knowledge Base:

257824 OL2000: Differences Between Outlook and Outlook Express

SYMPTOMS

If you open an e-mail message that was composed by a malicious e-mail author who used Multipurpose Internet Mail Extension Hypertext Markup Language (MHTML), files from the MHTML message may be placed in predictable locations on your hard disk. After the files are on your hard disk, the malicious e-mail message author can open these files that now run in the same security zone as those on your hard disk.

RESOLUTION

A supported fix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Apply it only to computers that are experiencing this specific problem. This fix may receive additional testing. Therefore, if you are not severely affected by this problem, Microsoft recommends that you wait for the next Microsoft Internet Explorer 5.01 service pack that contains this fix.

To resolve this problem immediately, download the fix by clicking the download link later in this article or contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, visit the following Microsoft Web site:NOTE: In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The usual support costs will apply to additional support questions and issues that do not qualify for the specific update in question.


The following files are available for download from the Microsoft Download Center:
For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base:

119591 How to Obtain Microsoft Support Files from Online Services

Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file. The Q261255.exe file contains the following files:
  • Inetcomm.dll
  • Msoe.dll
  • Msoert2.dll

Error Message When You Try to Install the Security Patch

This patch may not appear when you click Product Updates on the Microsoft Windows Update Web site, or you may receive the following message when you try to install this update from the Microsoft Download Center Web site:

This update does not need to be installed on this system.

This patch is only available for Internet Explorer 5.01. Microsoft Internet Explorer versions 4.0, 4.01, 4.01 Service Pack 1, and 5, are also vulnerable to this issue; however, when you run the patch on a version of Internet Explorer earlier than Internet Explorer 5.01, you receive the following message:

This update does not need to be installed on this system.

This patch is not listed as a critical update on the Microsoft Windows Update Web site unless you are running Internet Explorer 5.01.

Microsoft recommends that you upgrade to Internet Explorer 5.01 and then install this patch.

For additional information about how to determine which version of Internet Explorer is installed, click the article number below to view the article in the Microsoft Knowledge Base:

164539 How to Determine Which Version of Internet Explorer is Installed

Internet Explorer 5.01 Service Pack 1 and Internet Explorer 5.5

This issue is also resolved in Internet Explorer 5.01 Service Pack 1 (SP1) and Internet Explorer 5.5. To install either of these versions, use one of the following methods:
  • Install Internet Explorer 5.01 SP1 from one of the following locations:

    -or-

  • Install Internet Explorer 5.5 on any computer, except a Microsoft Windows 2000-based computer, from one of the following locations:

    -or-

    NOTE: If you install the patch on a Windows 2000-based computer, Internet Explorer 5.5 does not install upgraded Outlook Express components, and therefore does not eliminate the vulnerability. Windows 2000 users should install Internet Explorer 5.01 SP1.

    Windows 2000 users who have already installed Internet Explorer 5.5 and are concerned about this issue can remove Internet Explorer 5.5 by using the Add/Remove Programs tool in Control Panel, and then installing Internet Explorer 5.01 SP1.

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article.

MORE INFORMATION

For additional information about MHTML or other features in Internet Explorer 5, click the article number below to view the article in the Microsoft Knowledge Base:

221787 New Features in Internet Explorer 5


Modification Type:MinorLast Reviewed:8/5/2004
Keywords:kbdownload kbenv kbgraphxlinkcritical kbie501sp1Fix kbprb KB261253