Do I need to install all the updates listed in the Affected Software table for the software?
There are multiple update packages available for some affected software. Microsoft Office Compatibility Pack Service Pack 3 Non-Affected Software Office and Other Software
This update is available via Windows Update. See the **Update FAQ** for more information. This helps to maintain consistency for shared files across Office products. However, Microsoft recommends that users install all updates offered to their systems. Users who choose not to apply the updates for Microsoft Office 2010 Service Pack 2 will not increase the security risk for their system. ()Īlthough updates are available for Microsoft Office 2010 Service Pack 2, the software is not affected by the vulnerabilities described in this bulletin. Microsoft Office Suite and Other Software To determine the support life cycle for your software version or edition, see Microsoft Support Lifecycle.
Other versions or editions are either past their support life cycle or are not affected. The following software has been tested to determine which versions or editions are affected. Knowledge Base Article Knowledge Base Article See also the section, Detection and Deployment Tools and Guidance, later in this bulletin. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294871.įor administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update at the earliest opportunity using update management software, or by checking for updates using the Microsoft Update service. Customers who have not enabled automatic updating need to check for updates from Microsoft Update and install this update manually. Customers who have automatic updating enabled and configured to check online for updates from Microsoft Update typically will not need to take any action because this security update will be downloaded and installed automatically. Recommendation. Customers can configure automatic updating to check online for updates from Microsoft Update by using the Microsoft Update service. For more information about the vulnerabilities, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information. The security update addresses the vulnerabilities by correcting the way that Microsoft Office software parses specially crafted files. For more information, see the subsection, Affected and Non-Affected Software, in this section.
This security update is rated Important for supported editions of Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2013 RT software. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
An attacker who successfully exploited the most severe vulnerabilities could gain the same user rights as the current user.
The vulnerabilities could allow remote code execution if a specially crafted WordPerfect document file is opened in an affected version of Microsoft Office software. This security update resolves three privately reported vulnerabilities in Microsoft Office. Version: 1.0 General Information Executive Summary Security Bulletin Microsoft Security Bulletin MS13-091 - Important Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2885093)