MS16-148: Security Update for Microsoft Office to Address Remote Code Execution: December 13, 2016

Applies to: Excel 2016Office Home and Business 2016Office Home and Business 2016 More

Summary


This security update resolves vulnerabilities in Microsoft Office. To learn more about the vulnerabilities, see Microsoft Security Bulletin MS16-148.

More information about this security update


The following articles contain more information about this security update as it relates to individual product versions. These articles may contain known issue information.

Nonsecurity-related fixes and improvements that are included in this security update

  • Translate some terms into Slovak to make sure that the meaning is accurate.
  • When you insert content into cells in Microsoft Excel, Excel intermittently freezes on virtual machines and low-end devices.
  • When macros and some add-ins are included in operations to update the status bar text frequently, they are significantly slower in Office 2013 and 2016 than in earlier versions.
  • When you enable the desktop composition feature in Windows, Office 2013 application windows turn white.
  • When you rename a ribbon button that has a short command name through the customize ribbon dialog box, the command naming dialog box strips two special layout characters from the control name that's used in East Asian languages to control word breaking.
  • If you have content that's protected by IRM based on an admin template and the admin template is then archived, you can't do certain operations on it.
  • Skype for Business 2015 (Lync 2013) crashes during shutdown.
  • Translate some terms in multiple languages to make sure that the meaning is accurate.
  • When you run macro code to access the XML nodes in a custom XML part in a document in Microsoft Word 2016, you receive the following error message: 
    Run-time error -2147467259 (80004005): Reference to undeclared namespace prefix.

  • The check in, check out, and versioning functions don't work on a closed internal network with no Internet access. For example, when you try to check out a document, you receive the following error message:
    Microsoft Office cannot complete the operation because the network is unavailable. Check your network connection and try again.

  • After you close a document that's open in protected view in Excel 2016, Excel crashes.
  • When you send email message that have images in a high-DPI environment, the images are displayed in a larger size in a normal-DPI environment.
  • If you have content that's protected by IRM based on an admin template and the admin template is then archived, you can't do certain operations on the content.
  • Improve performance of rendering the custom filter list of items when the list contains long strings.
  • When a workbook is loaded in Microsoft SharePoint that has a PivotTable connected to a BISM file and it points to another workbook in the same farm, Power Pivot can't use some Korean DBCS characters in the formula bar.
  • It takes a long time to paste filtered selection data from large tables.
  • When an add-in or macro code tries to access a property on a shape control that no longer exists, Excel 2013 crashes. This update returns an error status instead of crashing.
  • For Excel 2016 and 2013, when you try to load HTML documents that contain <input/> tags in the protected view, you receive a corrupted file alert, and the documents can't be opened.
  • When you select cells by dragging on touch-enabled devices, Excel 2013 crashes because of interactions with accessibility (UIA) APIs that are on by default.
  • After you import a table that has multi-line columns and the Enhanced Rich Text function configured from SharePoint to Excel, the text in the multi-line columns is preceded by a blank line.
  • Improve performance of rendering the custom filter list of items when the list contains long strings.
  • When you use Excel 2016 with a printer that is added on the computer or with a printer that is accessible in a remote session, Excel 2016 crashes.
  • When you do a find-and-replace operation by using the clipboard marquee, you experience a slow performance.
  • When you switch single document interface (SDI) windows and select sheets in Excel 2016, Excel crashes.
  • Excel 2016 silently fails to complete loading a workbook. When this happens, the workbook may be functional, but you may be unable to save it.
  • When you try to load HTML documents that contain <input/> tags in the protected view, you receive a corrupted file alert, and the documents can't be opened.
  • It takes a long time to paste filtered selection data from large tables.
  • When an add-in or macro code tries to access a property on a shape control that no longer exists, Excel 2016 crashes. This update returns an error status instead of crashing.
  • The Solver Add-in fails to load.
  • This update makes handling of click events on embedded content more secure.

More Information