I didn't try on SP2 but it says it's also vulnerable. I got an email from a cc company that I applied for the other day, asking for info. It came a day or two after I applied but I refused to fill out even the minimal info they asked for because of stuff like this. Worse, the email used some javascript/crap to ask for the info in order to 'decrypt' the document... and I think it was legit but I still wouldn't take the chance.