MS13-094: Description of the security update for Outlook 2010: November 12, 2013

Introduction

This update resolves a security vulnerability in Microsoft Outlook that could allow information disclosure when a specially crafted email message is opened or previewed.

Summary

Microsoft has released security bulletin MS13-094. To view the complete security bulletin, go to one of the following Microsoft websites:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

More information about this security update

Download information

This update is available for download from the Microsoft Download Center:

Microsoft Outlook 2010 32-bit (x86) Service Pack 1 and Service Pack 2

Microsoft Outlook 2010 64-bit (x64) Service Pack 1 and Service Pack 2

Known issues with this security update

After this update is applied, you may experience issues with S/MIME certificate verification in Microsoft Outlook. This issue is caused because the update disables remote intermediate certificate fetching in Outlook.

If you experience these issues or if you are working in an enterprise installation that requires the retrieval of remote certificates referenced in an authority information access extension, a registry key can be set to enable remote intermediate certificate fetching in Microsoft Outlook.

Warning Setting the registry key to enable remote intermediate certificate fetching will remove the protections provided by this update.

Important
Follow the steps in this section carefully. Serious problems might occur if you modify the registry incorrectly. Before you modify it, back up the registry for restoration in case problems occur.

To enable remote intermediate certificate fetching in Outlook after this update is applied, set the following registry key value:

Registry location: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\14.0\Outlook\Security

DWORD name: EnableAIACertExtension
Value data: 1

Notes

  • You may have to create the Security subkey and the EnableAIACertExtension DWORD entry if they do not exist.

  • To disable the evaluation, set the Value data to 0 (0 is the default).


Additionally, you can apply this registry key change across domains by using Group Policy. For more information about Group Policy, see the TechNet article, Group Policy collection.

Prerequisites to apply this security update

To apply this security update, you must have Service Pack 1 or Service Pack 2 for Microsoft Office 2010 installed on the computer.

Restart information

You may have to restart the computer after you install this security update.

In some cases, this update does not require a restart. If the required files are being used, this update will require a restart. If this behavior occurs, a message is displayed that advises you to restart the computer.

To help reduce the possibility that a restart will be required, stop all affected services and close all applications that may use the affected files before you install this security update.

See Why you may be prompted to restart your computer after you install a security update on a Windows-based computer for more information.

Removal information

Note We do not recommend that you remove any security update.

To remove this security update, use the Add or Remove Programs item or use the Programs and Features item in Control Panel.

Note When you remove this security update, you may be prompted to insert the disc that contains Microsoft Office. Additionally, you may not have the option to uninstall this security update from the Add or Remove Programs item or the Programs and Features item in Control Panel. There are several possible causes for this issue.

See Information about the ability to uninstall Office updates for more information.

Security update replacement information

This security update replaces security update 2794707.

The English version of this security update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

For all supported x86-based versions of Outlook 2010

File name

File version

File size

Date

Time

Cnfnot32.exe_0004

14.0.7107.5000

152,744

08-Aug-2013

02:36

Contab32.dll

14.0.7107.5000

135,872

14-Aug-2013

05:36

Dlgsetp.dll

14.0.7107.5000

88,760

08-Aug-2013

02:36

Emsmdb32.dll_0005

14.0.7108.5000

1,756,928

18-Aug-2013

12:19

Envelope.dll

14.0.7107.5000

155,848

08-Aug-2013

02:36

Exsec32.dll_0001

14.0.7109.5000

332,952

07-Sep-2013

02:59

Impmail.dll

14.0.7107.5000

135,856

08-Aug-2013

02:36

Mapiph.dll

14.0.7107.5000

277,224

08-Aug-2013

02:36

Mimedir.dll

14.0.7107.5000

359,072

08-Aug-2013

02:36

Mspst32.dll_0004

14.0.7107.5000

1,264,888

14-Aug-2013

05:36

Olmapi32.dll

14.0.7109.5000

3,323,584

07-Sep-2013

02:59

Omsmain.dll

14.0.7107.5000

725,704

14-Aug-2013

05:44

Omsxp32.dll

14.0.7107.5000

234,200

14-Aug-2013

05:44

Outlmime.dll

14.0.7107.5000

523,984

08-Aug-2013

02:36

Outlook.exe

14.0.7109.5000

15,997,608

07-Sep-2013

02:59

Outlph.dll

14.0.7101.5000

330,456

23-Apr-2013

05:49

Outlvbs.dll_0001

14.0.7107.5000

56,504

08-Aug-2013

02:36

Pstprx32.dll

14.0.7107.5000

309,936

08-Aug-2013

02:36

Recall.dll

14.0.7005.1000

45,136

31-Oct-2012

07:39

Rm.dll

14.0.7107.5000

79,024

08-Aug-2013

02:36

Rtfhtml.dll

14.0.7005.1000

408,144

05-Nov-2012

08:08

Scanpst.exe_0002

14.0.7107.5000

40,168

08-Aug-2013

02:36

Scnpst32.dll

14.0.7107.5000

337,648

08-Aug-2013

02:36

Scnpst64.dll

14.0.7107.5000

348,408

08-Aug-2013

02:36

For all supported x64-based versions of Outlook 2010

File name

File version

File size

Date

Time

Cnfnot32.exe_0004

14.0.7107.5000

226,984

08-Aug-2013

02:41

Contab32.dll

14.0.7107.5000

179,392

14-Aug-2013

05:35

Dlgsetp.dll

14.0.7107.5000

118,456

08-Aug-2013

02:41

Emsmdb32.dll_0005

14.0.7108.5000

2,234,112

18-Aug-2013

12:19

Envelope.dll

14.0.7107.5000

220,360

08-Aug-2013

02:41

Exsec32.dll_0001

14.0.7109.5000

473,752

07-Sep-2013

02:57

Impmail.dll

14.0.7107.5000

187,056

08-Aug-2013

02:41

Mapiph.dll

14.0.7107.5000

423,144

08-Aug-2013

02:41

Mimedir.dll

14.0.7107.5000

543,904

08-Aug-2013

02:41

Mspst32.dll_0004

14.0.7107.5000

1,623,800

14-Aug-2013

05:35

Olmapi32.dll

14.0.7109.5000

4,551,872

07-Sep-2013

02:57

Omsmain.dll

14.0.7107.5000

1,098,440

14-Aug-2013

05:50

Omsxp32.dll

14.0.7107.5000

363,736

14-Aug-2013

05:50

Outlmime.dll

14.0.7107.5000

720,592

08-Aug-2013

02:41

Outlook.exe

14.0.7109.5000

24,064,168

07-Sep-2013

02:57

Outlph.dll

14.0.7101.5000

378,584

23-Apr-2013

05:48

Outlvbs.dll_0001

14.0.7107.5000

72,376

08-Aug-2013

02:41

Pstprx32.dll

14.0.7107.5000

428,720

08-Aug-2013

02:41

Recall.dll

14.0.7005.1000

57,424

31-Oct-2012

07:38

Rm.dll

14.0.7107.5000

100,528

08-Aug-2013

02:41

Rtfhtml.dll

14.0.7005.1000

549,456

05-Nov-2012

07:49

Scanpst.exe_0002

14.0.7107.5000

47,848

08-Aug-2013

02:41

Scnpst32.dll

14.0.7107.5000

451,312

08-Aug-2013

02:41

Scnpst64.dll

14.0.7107.5000

449,272

08-Aug-2013

02:41


Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

Thank you for your feedback!

×