Prerequisites
Microsoft has tested the versions of Windows and the versions of Outlook Express that are listed in this bulletin to assess whether they are affected by this vulnerability and to confirm that the update that this bulletin describes addresses this vulnerability.
To install the Outlook Express 6 Service Pack 1 (SP1) versions of this update, you must be running Internet Explorer 6 SP1 (version 6.00.2800.1106) on one of the following versions of Windows:
| • | Microsoft Windows NT Workstation 4.0 Service Pack 6a |
| • | Microsoft Windows NT Server 4.0 Service Pack 6a |
| • | Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6 |
| • | Microsoft Windows 2000 Service Pack 2, Service Pack 3, or Service Pack 4 |
| • | Microsoft Windows XP |
| • | Microsoft Windows XP Service Pack 1 |
| • | Microsoft Windows XP 64-Bit Edition Service Pack 1 |
To install the Outlook Express 6 for Windows Server 2003 versions of this update, you must be running Internet Explorer 6 (version 6.00.3790.0000) on Windows Server 2003 (32-bit or 64-bit), or you must be running Internet Explorer 6 (version 6.00.3790.0000) on Windows XP 64-Bit Edition Version 2003.
To install the Outlook Express 6 version of this update, you must be running Internet Explorer 6 (version 6.00.2600.0000) on a 32-bit version of Windows XP.
| • | Internet Explorer 5.01 Service Pack 4 (version 5.00.3700.1000) on Windows 2000 SP4 |
| • | Internet Explorer 5.01 Service Pack 3 (version 5.00.3502.1000) on Windows 2000 SP3 |
| • | Internet Explorer 5.5 Service Pack 2 (version 5.50.4807.2300) Windows Millennium Edition |
Versions of Windows, versions of Outlook Express, and versions of Internet Explorer that are not listed in this article are no longer supported. Although you can install some of the update packages that are described in this article on these versions of Windows and on these versions of Outlook Express, Microsoft has not tested these versions to assess whether they are affected by this vulnerability or to confirm that the update that this bulletin describes addresses this vulnerability. We recommend that you upgrade to a supported version of Windows and to a supported version of Outlook Express, and then apply the appropriate update.
For more information about how to determine the version of Internet Explorer that you are running, see Microsoft Knowledge Base Article 164539.
For more information about support lifecycles for Windows components, visit the following Microsoft Support Lifecycle Web site.
For more information about how to obtain the latest service pack for Internet Explorer 6, see Microsoft Knowledge Base Article 328548.
For more information about how to obtain the latest service pack for Internet Explorer 5.5, see Microsoft Knowledge Base Article 276369.
For more information about how to obtain the latest service pack for Internet Explorer 5.01, see Microsoft Knowledge Base Article 267954.
Restart Requirements
In some cases, this update does not require a restart. The installer stops the required services, applies the update, and then restarts the services. However, if the required services cannot be stopped for any reason or if required files are in use, this update will require a restart. If this occurs, a message appears that advises you to restart.
The Windows Server 2003 versions of this security update (including Windows XP 64-Bit Edition Version 2003) support the following setup switches:
/help Displays the command line options
Setup Modes
/quiet Quiet mode (no user interaction or display)
/passive Unattended mode (progress bar only)
/uninstall Uninstalls the package
Restart Options
/norestart Do not restart when installation is complete
/forcerestart Restart after installation
Special Options
/l Lists installed Windows hotfixes or update packages
/o Overwrite OEM files without prompting
/n Do not backup files needed for uninstall
/f Force other programs to close when the computer shuts down
Note You can combine these switches into one command. For backward compatibility, the security update also supports the setup switches that the previous version of the setup utility uses. For more information about the supported installation switches, see Microsoft Knowledge Base Article about the supported installation switches, see Microsoft Knowledge Base Article 262841.
Deployment Information
To install this security update on Windows Server 2003 without any user intervention, use the following command at a command prompt:
windowsserver2003-kb823353-x86-enu.exe /quiet /passive
To install this security update on Windows Server 2003 without forcing the system to restart, use the following command at a command prompt:
windowsserver2003-kb823353-x86-enu.exe /norestart
The other update packages for this security update support the following Setup switches:
/q Use Quiet mode or suppress messages when the files are being extracted.
/q:u Use User-Quiet mode. User-Quiet mode presents some dialog boxes to the user.
/q:a Use Administrator-Quiet mode. Administrator-Quiet mode does not present any dialog boxes to the user.
/t: path: Specify the location of the temporary folder that Setup uses or the target folder for extracting the files (when you also use the /c switch).
/c: Extract the files without installing them. If you do not specify the /t: path switch, you are prompted for a target folder.
/c: path Specify the path and the name of the Setup .inf file or the .exe file.
/r:n Never restart the computer after the installation process has completed.
/r:i Prompt the user to restart the computer if a restart is required, except when you use this switch together with the /q:a switch.
/r:a Always restart the computer after the installation process has completed.
/r:s Restart the computer after the installation process has completed without prompting the user.
/n:v Do not verify the version. Use this switch with caution to install the update on any version of Internet Explorer.
For more information about these supported setup switches, see Microsoft Knowledge Base Article 197147.
To install the security update without any user intervention, use the following command replacing "package_name" with the filename for the package being installed:
package_name /q:a /r:n
Verifying Update Installation
To verify the files that this security update has installed, use one of the following methods:
| • | Confirm that Q823353 appears in the Update Versions field in the About Internet Explorer dialog box. You cannot use this method on Windows Server 2003 or on Windows XP 64-Bit Edition Version 2003 because the package does not update the Update Versions field for these versions of Windows. |
| • | Compare the versions of the updated files on your computer with the files that are listed in the File Information section in this bulletin. |
| • | Confirm that the following registry entries exist: | • | For Windows Server 2003 and Windows XP 64-Bit Edition Version 2003, confirm that the Installed DWORD value that has a data value of 1 appears in the following registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB823353 | | • | For all other versions of Windows, confirm that the IsInstalled DWORD value that has a data value of 1 appears in the following registry key:HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{F5173CF0-1DFB-4978-8E50-A90169EE7CA9} |
|
Removal Information
To remove this update, use the Add or Remove Programs tool (or the Add/Remove Programs tool) in Control Panel. Click Outlook Express Q823353, and then click Change/Remove (or click Add/Remove).
On Windows Server 2003 and on Windows XP 64-Bit Edition Version 2003, system administrators can also use the Spuninst.exe utility to remove this security update. The Spuninst.exe utility is located in the %Windir%\$NTUninstallKB823353$\Spuninst folder. This utility supports the following setup switches:
/?: Show the list of installation switches.
/u: Use unattended mode.
/f: Force other programs to quit when the computer shuts down.
/z: Do not restart when the installation is complete.
/q: Use Quiet mode (no user interaction).
On all other versions of Windows, system administrators can use the Ieuninst.exe utility to remove this update. This security update installs the Ieuninst.exe utility in the %Windir% folder. This utility supports the following setup switches:
/?: Show the list of installation switches.
/z: Do not restart when the installation is complete.
/q: Use Quiet mode (no user interaction).
To remove this update quietly, use the following command at a command prompt:
c:\windows\ieuninst /q c:\windows\inf\q823353.inf
This command assumes that Windows is installed in the C:\Windows folder.
File Information
The English version of this security update has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.
Because of file dependencies, this update may contain additional files.For information about the specific security update for your operating system, click the appropriate link.
| Outlook Express 6 SP1 for Windows XP, Windows XP SP1, Windows 2000 SP3, Windows 2000 SP4, and Windows NT 4.0 SP6a |
Date Time Version Size File name
--------------------------------------------------------------
03-Mar-2003 23:57 6.0.2800.1123 75,776 Directdb.dll
07-Jun-2004 21:19 6.0.2800.1441 596,480 Inetcomm.dll
11-Oct-2002 22:08 6.0.2800.1123 47,616 Inetres.dll
03-Mar-2003 23:57 6.0.2800.1123 44,032 Msident.dll
03-Mar-2003 23:57 6.0.2800.1123 56,832 Msimn.exe
26-May-2004 21:26 6.0.2800.1437 1,175,040 Msoe.dll
03-Mar-2003 23:57 6.0.2800.1123 228,864 Msoeacct.dll
11-Oct-2002 22:09 6.0.2800.1123 2,479,616 Msoeres.dll
03-Mar-2003 23:57 6.0.2800.1123 91,136 Msoert2.dll
03-Mar-2003 23:57 6.0.2800.1123 93,184 Oeimport.dll
03-Mar-2003 23:57 6.0.2800.1123 55,808 Oemig50.exe
03-Mar-2003 23:57 6.0.2800.1123 31,744 Oemiglib.dll
03-Mar-2003 23:57 6.0.2800.1123 42,496 Wab.exe
24-Jun-2004 21:26 6.0.2800.1450 463,360 Wab32.dll
03-Mar-2003 23:57 6.0.2800.1123 30,208 Wabfind.dll
03-Mar-2003 23:57 6.0.2800.1123 77,824 Wabimp.dll
03-Mar-2003 23:57 6.0.2800.1123 27,648 Wabmig.exe
| Outlook Express 6 SP1 (64-Bit) for Windows XP 64-Bit Edition Service Pack 1 |
Date Time Version Size File name
--------------------------------------------------------------
03-Mar-2003 22:57 6.0.2800.1123 75,776 Directdb.dll
07-Jun-2004 20:18 6.0.2800.1441 593,408 Inetcomm.dll
11-Oct-2002 21:08 6.0.2800.1123 47,616 Inetres.dll
03-Mar-2003 22:57 6.0.2800.1123 44,032 Msident.dll
03-Mar-2003 22:57 6.0.2800.1123 56,832 Msimn.exe
02-Mar-2004 20:18 6.0.2800.1437 1,175,040 Msoe.dll
03-Mar-2003 22:57 6.0.2800.1123 228,864 Msoeacct.dll
11-Oct-2002 21:09 6.0.2800.1123 2,479,616 Msoeres.dll
03-Mar-2003 22:57 6.0.2800.1123 91,136 Msoert2.dll
03-Mar-2003 22:57 6.0.2800.1123 93,184 Oeimport.dll
03-Mar-2003 22:57 6.0.2800.1123 55,808 Oemig50.exe
03-Mar-2003 22:57 6.0.2800.1123 31,744 Oemiglib.dll
03-Mar-2003 22:57 6.0.2800.1123 42,496 Wab.exe
24-Jun-2004 20:18 6.0.2800.1450 463,360 Wab32.dll
03-Mar-2003 22:57 6.0.2800.1123 30,208 Wabfind.dll
03-Mar-2003 22:57 6.0.2800.1123 77,824 Wabimp.dll
03-Mar-2003 22:57 6.0.2800.1123 27,648 Wabmig.exe
| Outlook Express 6 for Windows XP |
Date Time Version Size File name
--------------------------------------------------------------
02-Jun-2004 19:00 6.0.2742.200 599,040 Inetcomm.dll
26-May-2004 21:59 6.0.2741.2600 1,175,552 Msoe.dll
| Outlook Express 6 for Windows Server 2003 |
Date Time Version Size File name Folder
--------------------------------------------------------------------
22-Jun-2004 22:38 6.0.3790.181 608,256 Inetcomm.dll RTMGDR
22-Jun-2004 22:38 6.0.3790.181 1,202,176 Msoe.dll RTMGDR
22-Jun-2004 22:38 6.0.3790.181 474,624 Wab32.dll RTMGDR
22-Jun-2004 22:46 6.0.3790.185 608,256 Inetcomm.dll RTMQFE
22-Jun-2004 22:46 6.0.3790.181 1,202,176 Msoe.dll RTMQFE
22-Jun-2004 22:46 6.0.3790.181 474,624 Wab32.dll RTMQFE
| Outlook Express 6 (64-Bit) for Windows Server 2003 64-Bit Editions and Windows XP 64-Bit Edition Version 2003 |
Date Time Version Size File name Platform
-----------------------------------------------------------------------
22-Jun-2004 22:40 6.0.3790.181 2,030,080 Inetcomm.dll IA64
22-Jun-2004 22:40 6.0.3790.181 4,085,760 Msoe.dll IA64
22-Jun-2004 22:40 6.0.3790.181 1,550,848 Wab32.dll IA64
22-Jun-2004 22:38 6.0.3790.181 608,256 Winetcomm.dll X86
22-Jun-2004 22:38 6.0.3790.181 1,202,176 Wmsoe.dll X86
22-Jun-2004 22:38 6.0.3790.181 474,624 Wwab32.dll X86
22-Jun-2004 22:48 6.0.3790.185 2,029,056 Inetcomm.dll IA64
22-Jun-2004 22:48 6.0.3790.181 4,085,760 Msoe.dll IA64
22-Jun-2004 22:48 6.0.3790.181 1,550,848 Wab32.dll IA64
22-Jun-2004 22:46 6.0.3790.185 608,256 Winetcomm.dll X86
22-Jun-2004 22:46 6.0.3790.181 1,202,176 Wmsoe.dll X86
22-Jun-2004 22:46 6.0.3790.181 474,624 Wwab32.dll X86
| Outlook Express 5.5 SP2 on Windows 2000 SP3, Windows 2000 SP4, and Windows Millennium Edition |
Date Time Version Size File name
--------------------------------------------------------------
04-Jun-2004 16:10 5.50.4942.400 575,248 Inetcomm.dll
04-Jun-2004 16:11 5.50.4942.400 1,147,152 Msoe.dll
Note When you install this security update on Windows Server 2003 or on Windows XP 64-Bit Edition Version 2003, the installer verifies whether one or more of the files that are being updated on your system have been updated previously by a Microsoft hotfix. If you have previously installed a hotfix to update one of these files, the installer copies the RTMQFE files to your system. Otherwise, the installer copies the RTMGDR files to your system. For more information, see Microsoft Knowledge Base Article 824994.