All Windows users need to be aware that Microsoft never links to downloads in its e-mail messages, but always requires a visit to a security bulletin landing page to download a patch.
If you receive an e-mail containing a link promising to upgrade Microsoft Outlook or Outlook Express, you should simply delete the message to avoid being nailed by a Trojan horse.
Any service pack can be problematic, but Vista Service Pack 2 (SP2) provides some extra-special challenges.
Vista SP1 offered clear benefits, including better performance, but with Vista’s second service pack you may just want to hold out for Windows 7’s release later this year.
Security updates for all versions of Internet Explorer have been released this week, although Microsoft rates as “Critical” only the patches for IE 8 (on all versions of Windows) and IE 7 (Vista SP2).
Version 8 of Microsoft’s browser is now being included in automatic Windows updates for all users, so be sure to uncheck the IE 8 option if for any reason you wish to postpone upgrading from IE 7 to IE 8.
You may already have been offered version 8 of Microsoft’s Internet Explorer browser via Windows’ built-in Automatic Updates routine, but you should be aware that some Web sites don’t work with the new release.
In my testing, IE 8’s security and compatibility settings cause problems with some sites, and XP users must first uninstall SP3 in order to remove the latest build of IE.
Previous Office service packs could be undone only by uninstalling the entire suite and then reinstalling it.
Office 2007 Service Pack 2 changes this and adds PDF and OpenDocument support, but I still urge you to wait before installing the update.
Two separate updates for all IE versions prevent carpet-bombing attacks that are already targeting the browser.
One of the IE patches blocks remote-code execution on XP and Vista PCs that also have Apple’s Safari browser installed.
Windows may be the primary target of today’s malware authors, but it’s far from the only one.
Keeping your applications and media players up-to-date is as important as applying the latest patches for your operating system.
If you installed XP Service Pack 3 or Windows Server SP2 after September 2008, you need to reapply an important security update.
In addition, if Windows Update offers your XP or Server 2003 system Microsoft’s security bulletin MS08-067 patch, you should install it — even if you’ve previously done so.