navigation bar left navigation bar right

Secunia CSI7
navigation left tab Advisories navigation right tab
navigation left tab Research navigation right tab
navigation left tab Forums navigation right tab
navigation left tab Create Profile navigation right tab
navigation left tab Our Commitment navigation right tab
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: Microsoft Outlook 2007 Insecure?

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
Microsoft
And, this specific program:
Microsoft Outlook 2007

This thread has been marked as locked.
mitchhellman Microsoft Outlook 2007 Insecure?
Member 16th Jul, 2010 01:50
Ranking: 0
Posts: 7
User Since: 29th Jan, 2010
System Score: N/A
Location: N/A
Upon running a scan today on my Windows XP machine using PSI v1.5.0.2, I received a notification that my Microsoft Outlook 2007 (version 12.0.6514.5000) is insecure; upon clicking on "Downlaod Solution" I am taken to the Microsoft Update site, which scans my computer and finds nothing out of date or missing at all. What to do?

This user no longer exists RE: Microsoft Outlook 2007 Insecure?
Member 16th Jul, 2010 08:59
Hi,

Some (if not most) updates for Microsoft Products and the Operating Systems, require that you reboot before scanning againg, as the updates do not "kick in" before a reboot. Please try rebooting and rescanning, and if you are still shown as insecure, checking Microsoft update and repeating the process.

hope this helps.
Was this reply relevant?
+0
-0
mitchhellman RE: Microsoft Outlook 2007 Insecure?
Member 16th Jul, 2010 20:27
Score: 0
Posts: 7
User Since: 29th Jan 2010
System Score: N/A
Location: N/A
Apparently you misunderstood me; Microsoft Update did not find any of my software to be out of date, so it did not download anything-- so no reboot would be necessary. Nonetheless, the system has been rebooted several times since I posted this and the problem persists; PSI says that Outlook needs to be patched, but Microsoft Update doesn't think so.

If you can tell me the version and location online of the patch (or of the latest version of Outlook 2007 containing the patch), I will attempt to download it manually rather than depend on Microsoft Update to do so-- but first let's verify that my copy of Outlook 2007 is indeed out-of-date.
Was this reply relevant?
+0
-0
mitchhellman RE: Microsoft Outlook 2007 Insecure?
Member 16th Jul, 2010 20:56
Score: 0
Posts: 7
User Since: 29th Jan 2010
System Score: N/A
Location: N/A
Further to my last message, this is the version of Outlook I am using:

Microsoft Outlook 2007 (12.0.6514.5000) SP2 MSO (12.0.6425.1000)
Was this reply relevant?
+0
-0
Anthony Wells RE: Microsoft Outlook 2007 Insecure?
Expert Contributor 16th Jul, 2010 20:59
Score: 2463
Posts: 3,348
User Since: 19th Dec 2007
System Score: N/A
Location: N/A
Last edited on 16th Jul, 2010 21:04
@mitchhellman ,

Secunia do not work on the PSI at the weekend , so while you wait here is some data on your version quoted :-

http://support.microsoft.com/kb/972363

and here is the latest Secunia Advisory for your software programme :-

http://secunia.com/advisories/40566/

Perhaps you can find your necessary patch/KB therein .

Let us know how you get on .

Anthony

PS: be sure that you are at Microsoft update and not Windows update when checking for Office updates .

PPS: here's the bulletin:-

http://www.microsoft.com/technet/security/bulletin...

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+1
-0
ddmarshall RE: Microsoft Outlook 2007 Insecure?
Dedicated Contributor 16th Jul, 2010 21:18
Score: 1219
Posts: 971
User Since: 8th Nov 2008
System Score: 98%
Location: UK
This is the Office Update which was issued this week:

http://www.microsoft.com/technet/security/bulletin...

You should see KB978212 successfully installed to be up to date.

Check the updates in Add/Remove Programs for any failed Office KB's which might be preventing this installing.

--
This answer is provided “as-is.” You bear the risk of using it.
Was this reply relevant?
+1
-0
mitchhellman RE: Microsoft Outlook 2007 Insecure?
Member 16th Jul, 2010 21:20
Score: 0
Posts: 7
User Since: 29th Jan 2010
System Score: N/A
Location: N/A
Anthony:

Thanks for your reply.

I have confirmed that I am in fact using Microsoft Update rather than Windows Update. I have also confirmed that KB972363 has previously been installed as it is listed in "Add or Remove Programs."
Was this reply relevant?
+0
-0
ddmarshall RE: Microsoft Outlook 2007 Insecure?
Dedicated Contributor 16th Jul, 2010 21:23
Score: 1219
Posts: 971
User Since: 8th Nov 2008
System Score: 98%
Location: UK
According to this:

http://support.microsoft.com/kb/980376/en-US/

Outlook.exe should be version 12.0.6535.5005

--
This answer is provided “as-is.” You bear the risk of using it.
Was this reply relevant?
+1
-0
Anthony Wells RE: Microsoft Outlook 2007 Insecure?
Expert Contributor 16th Jul, 2010 21:30
Score: 2463
Posts: 3,348
User Since: 19th Dec 2007
System Score: N/A
Location: N/A
Last edited on 16th Jul, 2010 21:34
Both ddmarshall and I have given you the link to the bulletin and the specific KB978212 that you need .

The (free) Belarc Advisor is a useful programme to cross check your security updates :-

http://belarc.com/free_download.html

Keep us up to date with your progress .

Anthony



--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+1
-0
ddmarshall RE: Microsoft Outlook 2007 Insecure?
Dedicated Contributor 16th Jul, 2010 22:05
Score: 1219
Posts: 971
User Since: 8th Nov 2008
System Score: 98%
Location: UK
Last edited on 16th Jul, 2010 22:07
Sorry, I've given you the wrong KB for the update. It should be KB980376. It's availalbe from the Download Center at:

http://www.microsoft.com/downloads/details.aspx?di...

Maybe there's something about your configuration that means the Update site isn't detecting you need the update. Sometimes Microsoft update their detection rules and you might find you then get it.

--
This answer is provided “as-is.” You bear the risk of using it.
Was this reply relevant?
+0
-0
Anthony Wells RE: Microsoft Outlook 2007 Insecure?
Expert Contributor 16th Jul, 2010 22:14
Score: 2463
Posts: 3,348
User Since: 19th Dec 2007
System Score: N/A
Location: N/A

@ddmarsall ,

Thank you for keeping an eye on things ddm , the correct KB980376 does show up in the bulletin when you/I/we scroll down to the Outlook 2007 SP2 solution . Just shows , can't be too careful .

Have to go now , so I'll leave Mitch in your most capable hands .

Take care

Anthony

--


It always seems impossible until its done.
Nelson Mandela
Was this reply relevant?
+0
-0
mitchhellman RE: Microsoft Outlook 2007 Insecure?
Member 17th Jul, 2010 02:08
Score: 0
Posts: 7
User Since: 29th Jan 2010
System Score: N/A
Location: N/A
Everyone:

Thanks again for your help. I found KB980376 on my own and downloaded it. Unfortunately, it failed with an error saying that "The detection failed, this can be due to a corrupted installation database."

I manually upgraded Windows Installer to version 4.5 (inclding a patch for this version) but the error still occurs.

From a scan of various boards that mention this, it doesn't look good. Several posters say that a solution involves digging into the registry and changing some folder names from "Patches" to "Patches_old" . I did this, rebooted and ran Microsoft Update again; it dowloaded and installed 3 more updates, but none were related to KB980376. I rebooted again and PSI still reported that Outlook 2007 was unpatched. I tried to run the KB980376 update again and got a different error this time: "The expected version of the product was not found on the system." I ran Office Diagnostics and there was no change in any of the above.

I'm going to run Repair from my original Office 2007 disk and see if anything happens.
Was this reply relevant?
+0
-0
jmcateer RE: Microsoft Outlook 2007 Insecure?
Member 21st Jul, 2010 16:56
Score: 0
Posts: 3
User Since: 22nd Nov 2008
System Score: N/A
Location: N/A
I am using MS VISTA and do not have MS Office/Outlook installed. Instead, I use the Open Office suite. PSI still informs me that I need to update, and similarly, there is nothing to update. Is there a way to get back to "green" since I have nothing to update?
Was this reply relevant?
+0
-0
wr RE: Microsoft Outlook 2007 Insecure?
Contributor 21st Jul, 2010 20:42
Score: 308
Posts: 739
User Since: 30th Mar 2008
System Score: 100%
Location: US
@jmcateer

Are you saying PSI is advising of a vulnerability
in Outlook/Office & that you have uninstalled it? If so
try this: To locate the exact file that the Secunia PSI has detected, use or switch to the ADVANCED interface, then :

1 Click on the + sign of the program to expand it.
2 Click on Technical Details in the Toolbox to see the installation path of the detected file.

If unsure of what to do next, COPY(Ctrl+c) & PASTE
(Ctrl+v) the results back here for additional help.

Hope this helps.

Regards, wr

--
HP Pavilion Slimline s3020n
Windows Vista Home Premium SP2 32 bit
AMD 64 Athlon X2
Firefox 31.3.0 ESR
The weakest link of a computer system is always sitting in front of the monitor.
Was this reply relevant?
+0
-0
gsmart RE: Microsoft Outlook 2007 Insecure?
Member 22nd Jul, 2010 06:51
Score: 7
Posts: 59
User Since: 30th May 2009
System Score: N/A
Location: AU
I think you will find that MS might not be supporting XP now also MS Outlook 10 has very recently been released and this makes the old "7" outdated

Keith
Was this reply relevant?
+0
-0
jmcateer RE: Microsoft Outlook 2007 Insecure?
Member 23rd Jul, 2010 01:05
Score: 0
Posts: 3
User Since: 22nd Nov 2008
System Score: N/A
Location: N/A
Technical details


Technical details about this installation of Microsoft Outlook 2007, you can use this information to determine why the Secunia PSI detected the program and the security state of it.

Version Detected:
12.0.6316.5000

Installation Path:
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

Last Inspection of Program:
21st Jul. 2010, 16:29 CET


Was this reply relevant?
+0
-0
wr RE: Microsoft Outlook 2007 Insecure?
Contributor 23rd Jul, 2010 01:16
Score: 308
Posts: 739
User Since: 30th Mar 2008
System Score: 100%
Location: US
on 21st Jul, 2010 16:56, jmcateer wrote:
I am using MS VISTA and do not have MS Office/Outlook installed. Instead, I use the Open Office suite. PSI still informs me that I need to update, and similarly, there is nothing to update. Is there a way to get back to "green" since I have nothing to update?


According to the file you posted M$ Office is installed on
your system. It should be populated in Add/Remove programs
& can be removed there if you don't wish to use it. If
not there go to the file detected by the PSI>right click>
choose Delete>click OK or close>restart> do full system
scan with the PSI.

Hope this helps.

Regards, wr


--
HP Pavilion Slimline s3020n
Windows Vista Home Premium SP2 32 bit
AMD 64 Athlon X2
Firefox 31.3.0 ESR
The weakest link of a computer system is always sitting in front of the monitor.
Was this reply relevant?
+0
-0
Maurice Joyce RE: Microsoft Outlook 2007 Insecure?
Handling Contributor 23rd Jul, 2010 01:54
Score: 11865
Posts: 9,101
User Since: 4th Jan 2009
System Score: N/A
Location: UK
@wr
The latest version of Microsoft Outlook is 12.0.6535.5005. There is an update feature embedded in Office 2007.

Is this a trial version of office that comes pre loaded on some new OEM PC's?

I ask because it may not be "updatable" until paid for after the 60 day trial.

U have recommended a right click deletion of the EXE file as a possible cure. Has this method been tried & tested because there are hundreds of files in the Office 12 Folder - what happens to the remainder?

As a long time user of Microsoft Office products I only uninstall via the original genuine disk (recommended) or Add/Remove.



--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+0
-0
jmcateer RE: Microsoft Outlook 2007 Insecure?
Member 23rd Jul, 2010 02:57
Score: 0
Posts: 3
User Since: 22nd Nov 2008
System Score: N/A
Location: N/A
wr,

Thanks for the info. All is now green. Evidently when I removed MS Office from the Add/Delete Programs population, it did not remove everything.

Thank you for your guidance.

James
Was this reply relevant?
+0
-0
wr RE: Microsoft Outlook 2007 Insecure?
Contributor 23rd Jul, 2010 03:39
Score: 308
Posts: 739
User Since: 30th Mar 2008
System Score: 100%
Location: US
You're welcome jmcateer-good to know all is well now.

@Maurice Joyce-now we know the rest of the story
about how to delete this program for future reference.
Good to hear from you. Will unsubscribe from this thread
for obvious reasons. Take care.

Regards, wr



--
HP Pavilion Slimline s3020n
Windows Vista Home Premium SP2 32 bit
AMD 64 Athlon X2
Firefox 31.3.0 ESR
The weakest link of a computer system is always sitting in front of the monitor.
Was this reply relevant?
+0
-0
Greatdane RE: Microsoft Outlook 2007 Insecure?
Member 23rd Jul, 2010 11:21
Score: -1
Posts: 11
User Since: 9th Sep 2009
System Score: N/A
Location: N/A
I'm using Windows XP Home, 32-bit and have automatic updates running daily for Microsoft updates. Have tried everything, including a patch for IE 8 and am still unable to find a solution for PSI's listed problem. Having Ad-Aware - it shows me an insecure email, which I delete. I Also have Spywareblaster, Spybot and Avast. All suggestions welcome! Thanks 'cause I'm at wits end!
Was this reply relevant?
+0
-0
MikeEugene RE: Microsoft Outlook 2007 Insecure?
Member 30th Jul, 2010 23:13
Score: 0
Posts: 3
User Since: 18th May 2009
System Score: N/A
Location: N/A
I continue to get a PSI error message that "MS Outlook 2007 insecure" even though MS download page says I have the KB980376 update installed. I do not use 2007, but rather MS Office 2003. I couldn't find a clear way to uninstall the 2007 Outlook that I never used. Maybe this is the problem? I also get "Scan Aborted" frequently and find that uninstalling PSI and reinstalling it cures that. Any suggestions? Thanks. Mike Eugene
Was this reply relevant?
+0
-0
Maurice Joyce RE: Microsoft Outlook 2007 Insecure?
Handling Contributor 30th Jul, 2010 23:34
Score: 11865
Posts: 9,101
User Since: 4th Jan 2009
System Score: N/A
Location: UK
I assume U have not got an original disk? This has a repair/remove option.

I have found this if it helps - sorry about the silly web page advert.

http://www.ehow.com/how_5103787_uninstall-outlook....

--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+0
-0
MikeEugene RE: Microsoft Outlook 2007 Insecure?
Member 30th Jul, 2010 23:49
Score: 0
Posts: 3
User Since: 18th May 2009
System Score: N/A
Location: N/A
thanks for the tips. Correct. No original disk. I followed the directions ("run"; "ok"...) No window came up after hitting "run." I suspect that never installing 2007 (Outlook and everything else, because I was happy with 2003 Office and didn't want to pay for 2007) might prohibit me from accessing files and paths to delete 2007.

I wonder if just leaving the 2007 Outlook as is without worrying about it will be a problem? I never use, never have, and don't plan to (but apparently I could if I change my mind and pay Microsoft...) My computer is almost 2 years old (Toshiba Sat L305-S5875.)

I have enjoyed 100% on PSI for almost 2 years, but can live with 99% that I now have with Outlook 2007 showing insecure, if it is not an issue.

But maybe I have missed something in how to deal with it... that is easy...
Was this reply relevant?
+0
-0
Maurice Joyce RE: Microsoft Outlook 2007 Insecure?
Handling Contributor 31st Jul, 2010 00:27
Score: 11865
Posts: 9,101
User Since: 4th Jan 2009
System Score: N/A
Location: UK
Last edited on 31st Jul, 2010 00:43
Try navigating using Windows Explorer to C:\Program Files\Microsoft Office\Office 12 (A folder)

This is Office 2007 - is there an uninstall option left there?

Just to confirm - are U saying U just have Outlook 2007 or have U still got the complete Microsoft Office 2007 trial version installed?

Edit:

Mike off to bed. If U have got Office 2007 on board this should fix it:

http://support.microsoft.com/kb/928218



--
Maurice

Windows 7 SP1 64 Bit OS
HP Intel Pentium i7
IE 11 for Windows 7 SP1
16GB RAM
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


Secunia is a member of FIRST Secunia is a member of EDUcause Secunia is a member of The Open Group Secunia is a member of FS-ISAC
 
Secunia © 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability - Disclaimer
follow Secunia on Facebook follow Secunia on Twitter follow Secunia on LinkedIn follow Secunia on YouTube follow Secunia Xing follow Secunias RSS feed follow Secunia on Google+