MS15-116: Description of the security update for Word 2013: November 10, 2015

Summary

This security update resolves vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. To learn more about these vulnerabilities, see Microsoft Security Bulletin MS15-116.

Note To apply this security update, you must have the release version of Service Pack 1 for Office 2013 installed on the computer. After you apply this security update, you may see a popup window that states that a website wants to open web content in protected mode in Internet Explorer. See Updates to change the way that Internet Explorer interacts with features in Microsoft Office applications for more information.

For a complete list of affected versions of Office software, see Microsoft Knowledge Base article 3104540.


Improvements and fixes

  • Adds the insert picture API to Office Add-ins for Word 2013, Excel 2013, and PowerPoint 2013. 
  • Adds two new add-in APIs under CustomXmlNode: getTextAsync and setTextAsync. These two new APIs also provide a way add a text value to a built-in CustomXmlNode object when the node has no text value yet.
  • This update also contains fixes for the following nonsecurity issues:
    • Assume that you have a document that has combo box content controls that are linked to custom XML parts in a document in Word 2013. After you select a value in one of these controls and then do an undo and a save operation, the type of some content controls is changed from combo box to rich text and loses the mapping to the node in the custom XML part.
    • When you use certain fonts to enter a nonbreaking hyphen to a document in Word 2013, a square is displayed instead of a nonbreaking hyphen.
    • The Do Not Forward business bar information string is cropped and isn't fully displayed in some non-English versions of Outlook 2013.
    • Assume that you have a document that has footnotes and both manual and automatic page breaks in Word 2013. You set the Numbering to Restart each page in the Footnote and Endnote dialog box. When you print a document in the background, footnote numbers in the printout are numbered consecutively instead of being restarted on each page.

How to get and install the update

Method 1: Microsoft Update

This update is available from Microsoft Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Get security updates automatically.

Note For Microsoft Office 2013 RT Service Pack 1, this update is available from Microsoft Update only.

Method 2: Microsoft Download Center

You can get the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

More Information

Security update deployment information

For deployment information about this update, see Microsoft Knowledge Base article 3104540.

Security update replacement information

This security update replaces previously released update 3055030.
File information
How to get help and support for this security update
Properties

Article ID: 3101370 - Last Review: Feb 15, 2017 - Revision: 2

Microsoft Office 2013 Service Pack 1, Microsoft Word 2013

Feedback