MS16-015: Security Update for Microsoft Office to Address Remote Code Execution: February 9, 2016

Summary

This security update resolves vulnerabilities in Microsoft Office. To learn more about the vulnerabilities, see Microsoft Security Bulletin MS16-015.

More information about this security update

The following articles contain more information about this security update as it relates to individual product versions. These articles may contain known issue information.

Nonsecurity-related fixes and improvements that are included in this security update

  • Adds telemetry that will help find the root cause of why rendering can stop working when the system is running low on memory.
  • Enables an add-in developer to receive a list of API requirement sets.
  • Includes translations for several terms in multiple languages to improve accuracy of meaning.
  • Makes sure that the calls to the Word API between client and servers are consistent. For example, if you insert a paragraph into a document, the reference ID is consistent between client and servers.
  • Enables an add-in developer to receive a list of API requirement sets.
  • Translates some functionalities in multiple languages for the accuracy of meaning and to avoid duplication.
  • Includes translations for several terms in multiple languages to improve the accuracy of meaning.
  • Contains fixes for the following nonsecurity issues:
    • OneNote 2010 may fail to synchronize a notebook that's shared with OneNote 2016 and you receive the error 0xE00001C5.
    • An Office add-in that overrides the default functionalities, such as copy or paste, and uses a delay loading can't be loaded in Office 2010 applications.
    • When you try to use the Save As function to save a document to a WebDAV server in an Office 2010 application, the Office 2010 application may crash. This issue occurs after you install October 13, 2015, update for Office 2010 (KB3055034) or later.
    • When you scroll HTML email messages in Outlook 2013 or Word 2013, Outlook 2013 or Word 2013 may stop responding.
    • If you step through codes (for example, use the Step Into function) in a document in Word 2013, Word 2013 may crash.
    • If you use Visual Studio Tools for Office (VSTO) tools to run some code in a document in Word 2013, a user selection is lost in the document.
    • When Office add-ins communicates with Word 2013, Word 2013 may go to sleep if there's no UI action and stop responding to add-ins.
    • If document uses some East Asian fonts, quotation marks might clash with neighboring characters.
    • Screen readers can't read document types in a document library.
    • When you insert multicolumn, multi-row, or text to a new SharePoint page, an additional column is created and text is shifted incorrectly.
    • Screen readers can't read or access information panels in SharePoint Server 2013.
    • You can't define a default value for a person or group field of a document set. The value should appear whenever a new item is created.
    • If the claim map cache fills up in SharePoint Server 2013, a race condition is created that causes poor user experience.
    • After you delete a SharePoint group from a site, certain SQL database may be locked. This causes farm availability issues.
    • Assume that you apply a SharePoint theme to a subsite. When you add an app to the subsite, the theme isn't applied to the app correctly.
    • If you start a crawl of a content source, the Mssearch.exe process causes high CPU usage.
    • If you apply more than one filter to a subtask, the parent task is filtered out and is no longer displayed.
    • Assume that you create a page on a site that has the SharePoint Server Publishing feature enabled. When you preview the page URL, hyphens are displayed in the URL instead of spaces.
    • The storage size of a site collection is decreased more than the original value during deletion of recycle bin items.
    • When you try to check in a file in a list but not in a document library, you receive the following error message:
      The object specified does not belong to a list.
    • After you install MS16-004: Description of the security update for SharePoint Foundation 2013: January 12, 2016, you can't view items in custom lists. Meanwhile, you receive the following error message:
      TypeError: Unable to get property 'replace' of undefined or null reference.
    • You can copy or save images of an IRM protected document in an Office Web App in Safari unexpectedly.
    • After you save a workbook that contains a link to an Excel Add-in to an OneDrive for Business folder, the link to the Excel Add-in may be broken.
    • When you use Excel 2016 to open a custom .xls file that isn't created in Excel, Excel 2016 may crash.
    • When Office add-ins communicates with Word 2016, Word 2016 may go to sleep if there's no UI action and stop responding to add-ins.
    • Assume that you save a document by using the Save As function in Word 2016. When you open the new document, the path of the linked document in the new document is changed unexpectedly.
    • Real Time Collaboration in Word 2016 could result in additional unnecessary locks on newly inserted paragraphs.
    • Incorrect output on paragraphs that have locks when Word 2016 merges a local document copy with changes on the server during Real Time Collaboration causes potential data duplication.
    • When you start a crawl for some content that has some links, the crawl fails because of the large number of links. After multiple failures, the content is deleted unexpectedly. After this update, you can set a maximum number of links to be sent to the index.
    • After you restore host header named site collections in SharePoint Server 2013, the site URLs of nondefault zones don't take the site URL configuration of the destination web application into account.
    • When you create a Visual Studio workflow and use the WaitForItemEvent activity against an item, the item ID is ignored.
    • It takes a long time to remove a column filter for a large table in Excel 2013. This issue occurs in Windows 8 or Windows 8.1 that has Narrator enabled, or on a Windows 10 touch-enabled device.
    • After you save a workbook that contains a link to an Excel Add-in to an OneDrive for Business folder, the link to the Excel add-in may be broken.
    • When you change a PivotTable filter in Excel 2013, you receive the following false error message:
      Operation cancelled by user.
    • If you open and close an add-in from a network location by using VBA in Excel 2013, the add-in may be deleted.
    • After you migrate from classic-mode to claims-based authentication in SharePoint Server 2013, you can't access the document author property. Meanwhile, the User Not Found exception is displayed.

More Information

Security update deployment information
How to get help and support for this security update
Properties

Article ID: 3134226 - Last Review: Jan 22, 2017 - Revision: 2

Excel 2016, Word 2016, Excel Services in SharePoint Server 2013, Microsoft Excel 2013, Microsoft Office 2013 Service Pack 1, Microsoft Office Web Apps Server 2013 Service Pack 1, Microsoft SharePoint Foundation 2013 Service Pack 1, Microsoft SharePoint Server 2013 Service Pack 1, Microsoft Word 2013, Excel Services in Microsoft SharePoint Server 2010, Microsoft Excel 2010, Microsoft Office 2010 Service Pack 2, Microsoft SharePoint Server 2010 Service Pack 2, Microsoft Word 2010, 2007 Microsoft Office Suite Service Pack 3, Excel Services in Microsoft Office SharePoint Server 2007, Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats, Microsoft Office Excel 2007, Microsoft Office Excel 2007 (Home and Student version), Microsoft Office Excel Viewer 2007, Microsoft Office SharePoint Server 2007, Microsoft Office Word 2007, Microsoft Office Word 2007 (Home and Student version), Microsoft Excel Web App, Microsoft Office Web Apps Service Pack 2, Word Viewer, Microsoft Office for Mac Academic 2011, Microsoft Office for Mac Home and Business 2011, Microsoft Office for Mac Home and Business 2011 Home Use Program, Microsoft Office for Mac Home and Student 2011, Microsoft Office for Mac Standard 2011, Microsoft Office 2016 for Mac

Feedback