MS14-082: Vulnerabilities in Microsoft Office could allow remote code execution: December 9, 2014


This security update resolves a vulnerability that could allow remote code execution or security feature bypass if a specially crafted file is opened in an affected edition of Microsoft Office.


Microsoft has released security bulletin MS14-082. Learn more about how to obtain the fixes that are included in this security bulletin:

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

More Information

Known issues and additional information about this security update

Known issues with this security update

  • After you install this security update, you may receive an error message that resembles any of the following when you insert a Forms ActiveX control (forms3) into an Office document, or when you edit the properties of a control:

    Visio cannot insert this control because its TypeInfo did not merge correctly. Ensure all parameter types are VBA friendly. Delete TEMP *.exd file if necessary.
    Object library invalid or contains references to object definitions that could not be found.
    Cannot insert object.
    The program used to create this object is Forms. That program is either not installed on your computer or it is not responding. To edit this object, install Forms or ensure that any dialog boxes in Forms are closed.
    Note In this error message, the Forms text may also be replaced by the GUID of the control.
For more information about how to resolve this issue, click the following article number to view the article in the Microsoft Knowledge Base:
3025036  "Cannot insert object" error in an ActiveX custom Office solution after you install the MS14-082 security update

The following articles contain additional information about this security update as it relates to individual product versions. The articles may contain known issue information. If this is the case, the known issue is listed below each article link.
  • 2726958 MS14-082: Description of the security update for Microsoft Office 2013: December 9, 2014
  • 2596927 MS14-082: Description of the security update for the 2007 Microsoft Office suite: December 9, 2014
  • 2553154 MS14-082: Description of the security update for Microsoft Office 2010: December 9, 2014

File hash information

Package NamePackage Hash SHA1Package Hash SHA2