Description of the security update for SharePoint Enterprise Server 2013: October 9, 2018

Applies to: Microsoft SharePoint Server 2013 Service Pack 1

Summary


This security update resolves vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. To learn more about these vulnerabilities, see Microsoft Common Vulnerabilities and Exposures CVE-2018-8480Microsoft Common Vulnerabilities and Exposures CVE-2018-8488Microsoft Common Vulnerabilities and Exposures CVE-2018-8498, and Microsoft Common Vulnerabilities and Exposures CVE-2018-8518.

Note To apply this security update, you must have the release version of Service Pack 1 for Microsoft SharePoint Server 2013 installed on the computer.

Improvements and fixes


This security update contains improvements and fixes for the following nonsecurity issues:
  • Assume that you type @ to mention someone in a post in Discussion, and the user is verified successfully. When you press the space key, the location of the cursor in the post is not set correctly.
  • When you click a document URL in the contents of the version of a document in the Document Set, the document isn't displayed, and you see a HTTP 404 error page. This issue occurs when the URL of the site collection contains a space.
  • This update adds the ability to search content of an Office365 Private Group from the on-premises search center in a hybrid search.

Known issues in this security update


When you try to move document sets to a records center after applying KB4461450, you may see an unexpected error. To resolve this issue, install the October 9, 2018, cumulative update for SharePoint Enterprise Server 2013 (KB4461458).

How to get and install the update


Method 1: Microsoft Update

This update is available from Microsoft Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to get security updates automatically, see Protect yourself online.

Method 2: Microsoft Update Catalog

To get the stand-alone package for this update, go to the Microsoft Update Catalog website.

Method 3: Microsoft Download Center

You can get the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

More Information


Security update deployment information

For deployment information about this update, see security update deployment information: October 9, 2018.

Security update replacement information

This security update replaces previously released security update KB 4092470.

File hash information

Package name SHA1 hash SHA256 hash
coreserverloc2013-kb4461450-fullfile-x64-glb.exe 3380FE7EE41739F0F9212326EA08D68004193D95 FF2992086316B616EDA0FB4D931A6A03C375BA6EB3200E7CC40EC15A5F454D60


File information

Download the file information for security update KB 4461450.

How to get help and support for this security update


Help for installing updates: Protect yourself online

Help for protecting your Windows-based computer from viruses and malware: Microsoft Secure

Local support according to your country: International Support