Microsoft says to read all e-mail in plain text rather than HTML, and lists no help for IE. For Vista, Microsoft says that IE 7's protected mode will defend against this attack in the new OS. Outlook 2007 isn't affected because it uses Word to display e-mail by default. Until there is a fix or at least a temporary workaround, use an alternate browser such as Firefox or Opera, and turn off HTML e-mail viewing in Outlook