MS16-107: Security update for Microsoft Office: September 13, 2016

Applies to: Excel 2016Office Home and Business 2016Office Home and Business 2016 More

Summary


This security update resolves a vulnerability in Microsoft Office. To learn more about the vulnerability, see Microsoft Security Bulletin MS16-107.

More information about this security update


The following articles contain more information about this security update as it relates to individual product versions. These articles may contain known issue information.

Nonsecurity-related fixes and improvements that are included in this security update

  • Enable the DialogAPI 1.1 requirement that is set in Office 2013 applications and the Mailbox 1.4 requirement that is set in Outlook 2013.
  • This is an update to a feature that was released in Office 2013. VBA macros are no longer automatically blocked when you receive an attachment from a trusted sender or you open a file from your personal OneDrive. See New feature in Office 2016 can block macros and help prevent infection and Plan security settings for VBA macros in Office 2016 for more information.
  • Translate some terms in multiple languages to make sure that the meaning is accurate.
  • Enable the DialogAPI 1.1 in Excel 2013.
  • Add some new and improved data connectivity and transformation features. For more information, see KB3118296.
  • Update translations of phone extension information in Outlook 2016 contacts for Skype for Business clients. Translate string changes for publishing settings in Visio 2016. Correct translations in Outlook rules wizard for Romanian.
  • Add OST corruption events.
  • Contains fixes for the following nonsecurity issues:
    • If slides contain an equation that has an animation applied, PowerPoint 2013 freezes in Slide Show mode.
    • After you export a presentation as a PDF file, intra-document hyperlinks will link to the correct slide.
    • After you export a presentation as a video, an audio that is set to play across slides stops on the correct slide.
    • After you save a workbook that has carriage return and line feed characters as a PDF file in Excel 2013, the characters are displayed as squares in Adobe Reader.
      Note To fix this issue, you also have to install April 5, 2016, update for Office 2013 (KB3085587).
    • After you rename a button on a custom ribbon tab in the Korean version of Office 2013 applications, the button name is split but remains on the same line.
    • You can't post a blog to a Blogger site in Word 2013. This update deletes the Blogger option from the Blog list because the authentication protocol is changed.
    • Assume that you disable the read receipt functionality in Outlook 2013. When you receive email messages that have a requested SMIME receipt, local copies of email messages bloat the Versions folder on the server that is running Exchange Server.
    • When you forward IRM email messages, the content is attached as an .msg attachment instead of being included in the message body in the new message.
    • A non-default Retention policy that is applied to shared mailboxes in Outlook does not apply to subfolders that are created in those mailboxes by any user who has permissions to that mailbox in Cached Exchange mode. This causes messages to be moved to those subfolders to inherit the parent folder's retention policy and not honor the policy that is set by the user. The messages will be deleted during the wrong period.
    • When you move a junkemail message from the Junk E-Mail folder, and you try to download the message again in Outlook 2013, the message is moved to the Junk E-Mailfolder again.
    • When you use a meeting request in Outlook 2013, Outlook 2013 crashes randomly.
    • The Sheets.Select (False) method doesn't work after you install MS16-088: Description of the security update for Excel 2013: July 12, 2016.
    • Excel 2013 opens HTML documents (even if they are renamed as .xls files) in protected view instead of silently failing. This issue occurs after you install MS16-088: Description of the security update for Excel 2013: July 12, 2016.
    • The Workbook.SendMail method doesn't work correctly to send a workbook through an email message in Excel 2016.
    • Accessibility applications such as screen readers can't recognize new content in cells in Excel 2016.
    • If you have multiple workbooks open concurrently in Excel 2016, and Auto-Recover is triggered on one of the workbooks, some of other workbooks that don't have any data models are corrupted.
    • Assume that an Excel worksheet object is embedded in another Office 2016 application, and the worksheet contains an ActiveX control. When you activate and deactivate the Excel object in the Office 2016 application, Excel 2016 crashes and you receive the following error message:
      The server application, source file or item cannot be found, or returned an unknown error. You may need to reinstall the server application.
    • The Sheets.Select (False) method doesn't work after you install MS16-088: Description of the security update for Excel 2016: July 12, 2016.
    • Excel 2016 opens HTML documents (even if they're renamed as .xls files) in protected view instead of silently failing.
    • After you save a workbook that has carriage return and line feed characters as a PDF file in Excel 2016, the characters are displayed as squares in Adobe Reader.
    • When you open the contact card to view the organization details for a user in OneDrive for Business, OneDrive for Business crashes.
    • You can't post a blog to a Blogger site in Word 2016. This update deletes the Blogger option from the Blog list because the authentication protocol is changed.
    • When you use an intended form to open an item in Outlook 2016, forms cache is corrupted and you receive the following error message:
      The custom form cannot be opened. Outlook will use an Outlook form instead. The form required to view this message cannot be displayed. Contact your administrator.
    • Assume that an email message is sent programmatically in Outlook 2016. When you try to send another email message to the same recipients, you don't get any suggestion for the recipient names. This issue occurs because the recipients aren't added to the nickname cache. See KB3115483 for more information.
    • Unexpected and unnecessary authentication notifications are displayed when you start in Outlook 2016.
    • After a search result is moved, the item persists in the results list.
    • You can't open public folders in Outlook 2016. This issue commonly affects Office 365 subscribers.
    • When you search items in the current folder in Outlook 2016, no preview is displayed if the Exchange Server version is earlier than 2016 and the Message Preview is set to 3 Lines.
    • When you move a junk email message from the Junk E-Mail folder, and you try to download the message again in Outlook 2013, the message is moved to the Junk E-Mail folder again.
    • When you use a meeting request in Outlook 2016, Outlook 2016 crashes randomly.
    • When you try to edit an appointment or meeting in Outlook 2016, the Browse Web Locations option is unavailable and you can't attach some files.
    • Consider the following scenario: You enable cached mode in Outlook 2016. You add two or more Exchange accounts to the same profile. You disable cached mode for those accounts, either manually or by Group Policy. You delete .ost files. In this scenario, Outlook 2016 can't send email messages, and the email messages are just stuck in the Outbox folder.
    • A non-default Retention policy that is applied to shared mailboxes in Outlook does not apply to subfolders that are created in those mailboxes by any user who has permissions to that mailbox in Cached Exchange mode. This causes messages to be moved to those subfolders to inherit the parent folder's retention policy and not honor the policy that is set by the user. The messages will be deleted during the wrong period.
    • When you select the Preview file button for a PDF file of an email message in Outlook 2016, the PDF file cannot be previewed.
    • Assume that you disable read receipt functionality in Outlook 2016. When you receive email messages that have a requested SMIME receipt, local copies of email messages bloat the Versions folder on the server that is running Exchange Server.
    • Attachments are rearranged, deleted, duplicated, or corrupted.
    • You can specify the default editor format for calendar items. For more information, see 3118318.
      Note This only sets the initial default format to be used when a calendar item is created. You can still select another format.

More Information