Description of the security update for Project 2013: November 13, 2018

Applies to: Project Standard 2013Project Professional 2013


This security update resolves vulnerabilities in Microsoft Office that could allow remote code execution if a user opens a specially crafted Office file. To learn more about these vulnerabilities, see Microsoft Common Vulnerabilities and Exposures CVE-2018-8575.
Note To apply this security update, you must have the release version of Microsoft Project 2013 Service Pack 1 installed on the computer.

Be aware that the update in the Microsoft Download Center applies to the Microsoft Installer (.msi)-based edition of Office 2013. It doesn't apply to the Office 2013 Click-to-Run editions, such as Microsoft Office 365 Home (see Determining your Office version).

Improvements and fixes

This security update contains improvements and fixes for the following nonsecurity issue:
Consider the following scenario:
  • You have a SharePoint document library.
  • The document library list experience is set to the new "modern" experience.
  • The document library versioning settings require checkout.
  • You have a Project file that is stored in the library.
  • You open the file from the library by using Project 2013.
In this situation, you find that the expected "checkout required" prompt isn't displayed, and therefore you can't respond to it. This means that if you make changes to the project and save, Project tells you that the changes can't be saved because checkout is required.

How to get and install the update

Method 1: Microsoft Update
This update is available from Microsoft Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to get security updates automatically, see Windows Update: FAQ.
Method 2: Microsoft Update Catalog
To get the stand-alone package for this update, go to the Microsoft Update Catalog website.
Method 3: Microsoft Download Center
You can get the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

More Information

Security update deployment information

For deployment information about this update, see security update deployment information: November 13, 2018.

Security update replacement information

This security update replaces previously released security update KB 3101506.

File hash information
File name SHA1 hash SHA256 hash
project2013-kb4461489-fullfile-x86-glb.exe CD33B48A3F5EA8761808FFA3DC9CF158B46E0238 81371A0B8E9819BFF5B3F95CEA2336FC6F76B006C8EBC0FABD440E245B6A7343
project2013-kb4461489-fullfile-x64-glb.exe B4E8AB72C27F361D39B5887602B58AF4B270617E 7FFA55E7F2B11C9776C5B628A88DC2740848D3C48606400A5B70137770AEB239
File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time together with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.

How to get help and support for this security update

Protect yourself online and at home: Windows Security support
Help for protecting your Windows-based computer from viruses and malware: Microsoft Secure
Local support according to your country: International Support