MS13-042: Description of the security update for Publisher 2010 Service Pack 1: May 14, 2013

Resolves a security vulnerability that exists in Microsoft Publisher 2010 Service Pack 1 that could allow arbitrary code to run when a specially crafted Publisher file is opened.
Microsoft has released security bulletin MS13-042. To view the complete security bulletin, go to one of the following Microsoft websites: 

How to obtain help and support for this security update

Help installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support

More information about this security update

Known issues with this security update

Microsoft Update or Windows Update may offer this update even though you do not have Microsoft Office Publisher 2010 installed. For more information about this issue, see Microsoft Update and Windows Update offer updates for Office programs that you do not have installed.

Prerequisites to apply this security update

To apply this security update, you must have Service Pack 1 for Microsoft Office 2010 installed on the computer. For information about how to obtain the service pack, see Description of Office 2010 SP1.

Restart information

You may have to restart the computer after you install this security update.

In some cases, this update does not require a restart. If the required files are being used, this update will require a restart. If this behavior occurs, a message is displayed that advises you to restart the computer.

To help reduce the possibility that a restart will be required, stop all affected services and close all applications that may use the affected files before you install this security update. For more information about the reasons why you may be prompted to restart, see Why you may be prompted to restart your computer after you install a security update on a Windows-based computer.

Removal information

Note We do not recommend that you remove any security update.

To remove this security update, use the Add or Remove Programs item or use the Programs and Features item in Control Panel.

Note When you remove this security update, you may be prompted to insert the disc that contains Microsoft Publisher 2010. Additionally, you may not have the option to uninstall this security update from the Add or Remove Programs item or the Programs and Features item in Control Panel. There are several possible causes for this issue.

For more information about the removal, see Information about the ability to uninstall Office updates.

Security update replacement information

This security update does not replace any previously released security update.

File information

The English version of this security update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
For all supported x86-based versions of Microsoft Publisher 2010 Service Pack 1
File nameFile versionFile sizeDateTime
For all supported x64-based versions of Microsoft Publisher 2010 Service Pack 1
File nameFile versionFile sizeDateTime
update security_patch security_update security bug flaw vulnerability malicious attacker exploit registry unauthenticated buffer overrun overflow specially-formed scope specially-crafted denial of service dos

Article ID: 2553147 - Last Review: 05/14/2013 17:11:00 - Revision: 1.0

Microsoft Office 2010 Service Pack 1

  • kbsecvulnerability kbsecurity kbsecbulletin kbfix kbexpertiseinter kbbug atdownload KB2553147