Summary

This security update resolves vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. To learn more about these vulnerabilities, see Microsoft Common Vulnerabilities and Exposures CVE-2018-1026 and  Microsoft Common Vulnerabilities and Exposures CVE-2018-1030.

Note To apply this security update, you must have the release version of Service Pack 1 for Microsoft Office 2013 installed on the computer.

Be aware that the update in the Microsoft Download Center applies to the Microsoft Installer (.msi)-based edition of Office 2013. It doesn't apply to the Office 2013 Click-to-Run editions, such as Microsoft Office 365 Home. (Determining your Office version)

How to get and install the update

Method 1: Microsoft Update

This update is available from Microsoft Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to get security updates automatically, see Windows Update: FAQ.

Method 2: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

Method 3: Microsoft Download Center

You can get the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

More Information

Security update deployment information

For deployment information about this update, see security update deployment information: April 10, 2018.

Security update replacement information

This security update replaces previously released security update 4011277.

File hash information

Package name

Package hash SHA 1

Package hash SHA 2

oart2013-kb4018288-fullfile-x86-glb.exe

9C74A4CBE608FC0F51D3709107AF8EFBE86C347B

124AA253761649E7EA756EB903C04F929D9C14F10E8AF1105063D335C79FBF68

oart2013-kb4018288-fullfile-x64-glb.exe

7599C136FD0A2B69FBD2C24BFF5C06BCED67AB19

6BA80F0CF9FE95CBC467B6D4A4A05892E61D28142691E363BA62C65A11A11BA0

File information

The English version of this security update has the file attributes (or later file attributes) that are listed in the following table.

For all supported x86-based versions of Office 2013

File identifier

File name

File version

File size

Date

Time

igx.dll

igx.dll

15.0.5015.1000

8990880

14-Mar-18

08:19

oart.dll

oart.dll

15.0.5023.1000

14453952

14-Mar-18

08:19

oartodf.dll

oartodf.dll

15.0.5015.1000

2139336

14-Mar-18

08:19

For all supported x64-based versions of Office 2013

File identifier

File name

File version

File size

Date

Time

igx.dll

igx.dll

15.0.5015.1000

10371752

14-Mar-18

08:19

xlsrv.ecs.igx.dll

igx.dll

15.0.5015.1000

10371752

14-Mar-18

08:19

oart.dll

oart.dll

15.0.5023.1000

21245112

14-Mar-18

08:19

xlsrv.ecs.oart.dll

oart.dll

15.0.5023.1000

21245112

14-Mar-18

08:19

oartodf.dll

oartodf.dll

15.0.5015.1000

3783880

14-Mar-18

08:19

xlsrv.ecs.oartodf.dll

oartodf.dll

15.0.5015.1000

3783880

14-Mar-18

08:19

How to get help and support for this security update

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

Propose a feature or provide feedback on Office Core: Office User Voice portal

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

What affected your experience?

Any additional feedback? (Optional)

Thank you for your feedback!

×