For the Exchange / RTF / TNEF thing, there's a set of patches for client PCs (Outlook 2000, 2002 and 2003) and a set of patches for Exchange (5.0, 5.5 and 2000).

I've read the bulletin and I'm unclear as to whether you just need to patch the server OR the client or the server AND the client. Does anyone have any thoughts on this?