MS16-004: Security Update for Microsoft Office to Address Remote Code Execution: January 12, 2016

Summary

This security update resolves a vulnerability in Microsoft Office. To learn more about the vulnerability, see Microsoft Security Bulletin MS16-004.

More information about this security update

The following articles contain more information about this security update as it relates to individual product versions. These articles may contain known issue information.
  • 2881029 MS16-004: Description of the security update for Office 2010: January 12, 2016
  • 2881067 MS16-004: Description of the security update for the 2007 Microsoft Office Suite: January 12, 2016
  • 2920727 MS16-004: Description of the security update for Office 2016: January 12, 2016
  • 3039794 MS16-004: Description of the security update for Office 2013: January 12, 2016
  • 3096896 MS16-004: Description of the security update for Microsoft Visual Basic Runtime 6.0: January 12, 2016
  • 3114396 MS16-004: Description of the security update for PowerPoint 2010: January 12, 2016
  • 3114402 MS16-004: Description of the security update for Visio 2010: January 12, 2016
  • 3114421 MS16-004: Description of the security update for Visio 2007: January 12, 2016
  • 3114429 MS16-004: Description of the security update for PowerPoint 2007: January 12, 2016
  • 3114482 MS16-004: Description of the security update for PowerPoint 2013: January 12, 2016
  • 3114486 MS16-004: Description of the security update for Office 2013: January 12, 2016
  • 3114489 MS16-004: Description of the security update for Visio 2013: January 12, 2016
  • 3114494 MS16-004: Description of the security update for Word 2013: January 12, 2016
  • 3114503 MS16-004: Description of the security update for SharePoint Foundation 2013: January 12, 2016
  • 3114504 MS16-004: Description of the security update for Excel 2013: January 12, 2016
  • 3114511 MS16-004: Description of the security update for Visio 2016: January 12, 2016
  • 3114518 MS16-004: Description of the security update for PowerPoint 2016: January 12, 2016
  • 3114520 MS16-004: Description of the security update for Excel 2016: January 12, 2016
  • 3114526 MS16-004: Description of the security update for Word 2016: January 12, 2016
  • 3114527 MS16-004: Description of the security update for Office 2016: January 12, 2016
  • 3114540 MS16-004: Description of the security update for Excel 2007: January 12, 2016
  • 3114541 MS16-004: Description of the security update for the 2007 Microsoft Office Suite: January 12, 2016
  • 3114546 MS16-004: Description of the security update for Office Compatibility Pack Service Pack 3: January 12, 2016
  • 3114547 MS16-004: Description of the security update for Excel Viewer 2007: January 12, 2016
  • 3114549 MS16-004: Description of the security update for Word 2007: January 12, 2016
  • 3114553 MS16-004: Description of the security update for Office 2010: January 12, 2016
  • 3114554 MS16-004: Description of the security update for Office 2010: January 12, 2016
  • 3114557 MS16-004: Description of the security update for Word 2010: January 12, 2016
  • 3114564 MS16-004: Description of the security update for Excel 2010: January 12, 2016
  • 3114569 MS16-004: Description of the security update for Word Viewer: January 12, 2016
  • 3133699 MS16-004: Description of the security update for Office for Mac 2011: January 12, 2016
  • 3133711 MS16-004: Description of the security update for Office 2016 for Mac: January 12, 2016

Known issues in this security update

  • After you apply security update 2881067, 2881029, 3039794, or 2920727, you have problems that affect your Access database if you use certain Windows common controls. Specifically, these problems occur if you use the controls that are associated with the MSCOMCTL.OCX file that's updated in the security update. For more information, click the following article number to view the article in the Microsoft Knowledge Base:
    3139567 Error messages or Access crashes after you install security update MS16-004

Nonsecurity-related fixes and improvements that are included in this security update

  • Improves grid display performance when you enter data and formulas in the presence of split or freeze panes in Excel 2013.
  • Adds a function to set the SPWeb.RequestAccessEmail property by using a client-side object model (CSOM).
  • Translates some terms in multiple languages to make sure that the meaning is accurate.
  • Contains fixes for the following nonsecurity issues:
    • The Font.TintAndShade property doesn't work in Excel object model.
    • When you try to close a workbook that's opened by a modal userform, the workbook that contains the macro and the userform is closed unexpectedly.
    • When you check permissions, incorrect permissions are reported based on group memberships across trusted domain boundaries. Therefore, an external token isn't populated with security groups of trusted domains.
    • If a SQL Server Report Viewer Web Part is created before Service Pack 1 was applied, a page that contains the Report Viewer Web Part can't be loaded, and you receive the following error message:
      You must first select a report to display in this Web Part. Do this by opening the tool pane and specifying the path and file name of the Reporting Services report that you would like to show. Alternatively, you can connect the Web Part to another Web Part on the page that provides a document path.
    • After you create a view on a publishing sub site, the view is displayed in datasheet view. Meanwhile, you receive the following error message:
      The list is displayed in Standard view. It cannot be displayed in Datasheet view for one or more of the following reasons: A datasheet component compatible with Microsoft SharePoint Foundation is not installed, your browser does not support ActiveX controls, a component is not properly configured for 32-bit or 64-bit support, or support for ActiveX controls is disabled.
    • When you click the Save button multiple times on the ribbon to add an item to a list, the item is added multiple times.
    • When you try to update the configuration database for the host-named site collections by using the SPContentDatabase.RefreshSitesInConfigurationDatabase method, the sites become unavailable if the site collections are set in content databases that are separate from the root site collection.
    • Assume that you have a site collection that has the document ID feature enabled or a URL field that points to a resource within the site collection. Then, you check out a document and move the content database of the site collection to another web application. After you check in the document, the URL of the document points to the old site.
    • When you try to insert an HTML file as an object in a Word 2013 document, you receive the following error message:
      The program used to create this object is html file. That program is either not installed on your computer or it is not responding. To edit this object, install html file or ensure that any dialog boxes in html file are closed.
    • If the default input language is set to a language that uses Cyrillic characters, some keyboard shortcuts (for example, Ctrl+C and Ctrl+V) do not work in Word 2013.
    • A Universal Naming Convention (UNC) path that contains some full-width characters isn't resolved as a hyperlink in Word 2013.
    • It takes longer than expected to update the custom XML in the XML Mapping pane in Word 2013.
    • After you save a Visio drawing that contains ActiveX controls and VBA macros in Visio 2013, the digital signature is lost.
    • When you click a hyperlink in a Visio document that's located on a SharePoint 2013 server, the linked file doesn't open. This issue occurs if the name of the linked file contains characters that are not in the Latin character set (for example, Cyrillic letters).
    • After you use the Office deployment tool to install Office 2013 Click-to-Run editions that have multiple language packs, the language that is set in the config.xml as the first language isn't set as the default language.
    • After you save an Excel workbook that contains an unregistered ActiveX control in Excel 2013, Excel 2013 crashes.
    • When you try to open a file that's encrypted by a custom encryption provider in an Office 2013 application, the application crashes.
    • Assume that you delete a cell comment of a cell that has a fill effect in a workbook in Excel 2013. Then, you save the workbook. When you reopen the file, you receive the following error message:
      Excel found unreadable content in 'workbookname.xlsx'. Do you want to recover the contents of this workbook? If you trust the source of this workbook, click Yes.
      After you select the Yes button, you receive the following error message:
      Excel was able to open the file by repairing or removing the unreadable content.
    • After you install the November 10, 2015 update for Office 2013 (KB3101360) or the December 8, 2015 update for Office 2013 (KB3114333), Office applications may hang or crash. This may affect one or more Office applications, such as Outlook 2013, Word 2013, Excel 2013, OneNote 2013, and PowerPoint 2013.
    • When you try to use PowerPoint 2013 to open a presentation in SharePoint Server in protected mode in Internet Explorer, you receive the following error message:
      Sorry, we couldn't find C:\users\<userid>\Desktop\%u. Is it possible it was moved, renamed, or deleted?
    • Assume that you create a bookmark for more than one paragraph in an email message in Outlook 2016. Then, you send the email message. When you check the bookmark of the message, an incorrect selection is displayed.
    • You can't save a document to a document library that has a required column in Word 2016.
    • When you use a Japanese input method editor in Word 2016, you experience the following issues:
      • Certain special characters, such as circled numbers, aren't displayed correctly.
      • Backspace and delete operations do not work.
      • Selecting an item from a candidate list doesn't work.
    • When you use certain fonts to enter a nonbreaking hyphen in a document in Word 2016, a square is displayed instead of a nonbreaking hyphen.
    • It takes a long time to clear a column filter for a large workbook in Excel 2016 on a Windows 10-based computer.
    • When you print or print preview a worksheet in Excel 2016, the name of a group box (form control) is displayed in an incorrect position.
    • Sometimes you receive an out-of-memory error when you create a new Excel window after you use an Excel preview window in Outlook.
    • Assume that you create a workbook that contains a new type chart (a treemap, sunburst, histogram, box and whisker, Pareto, or waterfall chart) in an installation of Excel 2016 that has security update 3101351 installed. Then, you change the workbook in Excel 2016 RTM. When you reopen the workbook in Excel 2016, the chart is disconnected from the data source.
    • When you try to use PowerPoint 2016 to open a presentation in SharePoint Server in protected mode in Internet Explorer, you receive the following error message:

      Sorry, we couldn't find C:\users\<userid>\Desktop\%u. Is it possible it was moved, renamed, or deleted?

More Information

Security update deployment information
How to get help and support for this security update
Properties

Article ID: 3124585 - Last Review: Jan 22, 2017 - Revision: 2

Microsoft Office Home and Business 2016, Microsoft Office Home and Business 2016, Microsoft Office Home and Business 2016, Microsoft Office Home and Business 2016, Microsoft Office Home and Student 2016, Microsoft Office Home and Student 2016, Microsoft Office Home and Student 2016, Microsoft Office Home and Student 2016, Microsoft Office Personal 2016, Microsoft Office Professional 2016, Microsoft Office Professional 2016, Microsoft Office Professional 2016, Microsoft Office Professional 2016, Microsoft Office Professional 2016, Microsoft Office Professional 2016, Microsoft Office Professional 2016, Microsoft Office Professional 2016, Microsoft Office Professional 2016, Microsoft Office Professional Plus 2016, Microsoft Office Standard 2016, Word 2016, Microsoft Office 2013 Service Pack 1, Microsoft Word 2013, Microsoft Office 2010 Service Pack 2, Microsoft PowerPoint 2010

Feedback