Attachment Insecurity Revealed in Outlook Express

Attachment Insecurity Revealed in Outlook Express

Oct 6, 2004
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Outlook Express 6 includes a configuration setting awkwardly titled “Do not allow attachments to be saved or opened that could potentially be a virus.” When this option is checked, OE blocks the user from opening a wide variety of attachment types that have the potential to execute some kind of code.

Clicking the paperclip icon in preview mode shows the attachment names, but the menu options to save or open them are grayed out. When the message is opened, OE displays a banner stating, “OE removed access to the following unsafe attachments in your mail:.”

Windows XP Professional administrators can lock down this setting using the Group Policy Editor, so it might seem a useful way to prevent children or employees from inadvertently releasing potential viruses.

But theres a gaping hole in the security provided by this setting. If the user clicks Forward, the attachment is displayed in the forwarded message, and a double click will launch it.

To read the full story at PCMag.com,

click here.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.