MS15-022: Description of the security update for Word 2010: March 10, 2015

Applies to: Microsoft Word 2010

Introduction


This security update resolves vulnerabilities in Microsoft Office that could allow remote code execution if an attacker convinces a user to open or preview a specially crafted Microsoft Word file in an affected version of Office.

Improvements and fixes

This update also contains fixes for the following nonsecurity issues:
  • When text that contains an interpunct is copied from Microsoft Word 2010 and then pasted into Word as a plain text, the interpunct changes to a bullet character unexpectedly.
  • Assume that you have the preview pane enabled in the Open dialog box in an Office 2010 application, and you select a file. In this situation, you receive an error message in the preview pane. For example, you receive the following error message in Word 2010:
    This file can't be previewed because of an error in the Microsoft Word previewer.
  • Document properties in the ODF format are not restored as fields if you use the Close button and then save the document.
  • Updates Word 2010 to work correctly with design changes that were made to the Microsoft Forms ActiveX Control (FM20.dll) shared component library. For more information, see the following Microsoft Knowledge Base article:
    3025036 "Cannot insert object" error in an ActiveX custom Office solution after you install the MS14-082 security update


  • If a multipage document has protected form fields, you cannot browse through the document by using the Previous Page and Next Page buttons in print preview.

Summary


Microsoft has released security bulletin MS15-022. Learn more about how to obtain the fixes that are included in this security bulletin:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security support and troubleshooting

Help protect your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International support

More information about this security update

Download information

This update is available for download from the Microsoft Download Center.

Known issues with this security update

This security update opts Microsoft Word, Excel, or PowerPoint into local computer lockdown, a feature control for Internet Explorer, to prevent scripts in Office documents from running with elevated user rights.

Specifically, in a side-by-side scenario of Office 2003 and either the 2007 Microsoft Office suite or Office 2010, the changed registry keys in this security update may also affect Office 2003. This may cause some unexpected behavior in Office 2003.

Workaround

ActiveX kill bits may be used to completely block ActiveX controls that could lead to HTML script execution.




Prerequisites to apply this security update

To apply this security update, you must have Service Pack 2 for Office 2010 installed on the computer.

Restart information

You may have to restart the computer after you install this security update.

In some cases, this update does not require a restart. If the required files are being used, this update will require a restart. If this behavior occurs, a message is displayed that advises you to restart the computer.

To help reduce the possibility that a restart will be required, stop all affected services and close all applications that may use the affected files before you install this security update.

Learn about why you may be prompted to restart your computer after you install a security update on a Windows-based computer.

Removal information

Note We do not recommend that you remove any security update.

To remove this security update, use the Add or Remove Programs item or the Programs and Features item in Control Panel.

Note When you remove this security update, you may be prompted to insert the disc that contains Microsoft Office. Additionally, you may not have the option to uninstall this security update from the Add or Remove Programs item or the Programs and Features item in Control Panel. There are several possible causes of this issue.

Learn about the ability to uninstall Office updates .

Security update replacement information

This security update replaces update 2956066.