This security update resolves vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. To learn more about these vulnerabilities, see Microsoft Common Vulnerabilities and Exposures CVE-2018-8244.
Note To apply this security update, you must have the release version of Microsoft Outlook 2016 installed on the computer.
Be aware that the update in the Microsoft Download Center applies to the Microsoft Installer (.msi)-based edition of Office 2016. It doesn't apply to the Office 2016 Click-to-Run editions, such as Microsoft Office 365 Home (see Determining your Office version).
Improvements and fixes
- When you open and edit a document that is stored in a folder in Outlook 2016, the changes are not saved.
Sync Slider settings do not work for group conversations.
When you send an RTF-formatted email message that has attachments in online mode of Outlook 2016, one or more attachments may become corrupted.
This update improves the translation about forwarding a meeting in Outlook 2016 for all languages.
After the primary email address of a user profile is changed, Outlook 2016 still shows the old SMTP address for the user profile.
When you open a digitally signed email message from the Sent folder and send it again in Outlook 2016, Outlook 2016 may crash.
If the PR_EMSMDB_CRED_USERNAME property is not present in user profiles, some users may experience too many calls to the user principal name (UPN) lookup. To fix this issue, follow the instructions in KB 4022165.
You cannot attach local network items through the recent items list in Outlook 2016 if the Internet connection is unavailable.
Some cloud attachments that have certain file names are invisible in email messages.
After a cross-forest migration or a migration to Microsoft Office 365, some users who have existing profiles cannot send email messages.
If you add an attachment to an RTF-formatted email message through copy and paste (drag-and-drop) in Outlook 2016, the attachment may be lost when you send the email.
After you install or update an Outlook add-in in Outlook 2016, multiple network calls (getAppManifest calls) will be made to retrieve Exchange add-in manifest data.
How to get and install the update
Method 1: Microsoft Update
This update is available from Microsoft Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to get security updates automatically, see Windows Update: FAQ.
Method 2: Microsoft Update Catalog
To get the stand-alone package for this update, go to the Microsoft Update Catalog website.
Method 3: Microsoft Download Center
You can get the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.
Security update deployment information
For deployment information about this update, see security update deployment information: June 12, 2018.
Security update replacement information
This security update replaces previously released security update KB 4011682.
File hash information
|File name||SHA1 hash||SHA256 hash|
The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.