Microsoft Office Defense in Depth Update
Released: Nov 14, 2017
Last updated: Nov 28, 2017
- Assigning CNA
- Microsoft
Executive Summary
Microsoft has released an update for Microsoft Office that provides enhanced security as a defense in depth measure.
Exploitability
The following table provides an exploitability assessment for this vulnerability at the time of original publication.
- Publicly disclosed
- No
- Exploited
- No
- Exploitability assessment
FAQ
I have Microsoft Word 2010 installed. Why am I not being offered the 4011268 update? The 4011268 update only applies to systems running specific configurations of Microsoft Office 2010. Some configurations will not be offered the update.
I am being offered this update for software that is not specifically indicated as being affected in the Affected Software and Vulnerability Severity Ratings table. Why am I being offered this update? When updates address vulnerable code that exists in a component that is shared between multiple Microsoft Office products or shared between multiple versions of the same Microsoft Office product, the update is considered to be applicable to all supported products and versions that contain the vulnerable component.
For example, when an update applies to Microsoft Office 2007 products, only Microsoft Office 2007 may be specifically listed in the Affected Software table. However, the update could apply to Microsoft Word 2007, Microsoft Excel 2007, Microsoft Visio 2007, Microsoft Compatibility Pack, Microsoft Excel Viewer, or any other Microsoft Office 2007 product that is not specifically listed in the Affected Software table. Furthermore, when an update applies to Microsoft Office 2010 products, only Microsoft Office 2010 may be specifically listed in the Affected Software table. However, the update could apply to Microsoft Word 2010, Microsoft Excel 2010, Microsoft Visio 2010, Microsoft Visio Viewer, or any other Microsoft Office 2010 product that is not specifically listed in the Affected Software table.
For more information on this behavior and recommended actions, see Microsoft Knowledge Base Article 830335. For a list of Microsoft Office products that an update may apply to, refer to the Microsoft Knowledge Base Article associated with the specific update.
Acknowledgements
Security Updates
To determine the support lifecycle for your software, see the Microsoft Support Lifecycle.
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
- -
Disclaimer
Revisions
Revised the Affected Products table to include Microsoft Office Online Server 2016 because the update also provides enhanced security as a defense-in-depth measure. Microsoft recommends that customers running Office Online Server 2016 install update 4011020 for these enhanced security measures.
Added an Update FAQ to explain why some customers are not being offered update 4011268. Added an Update FAQ to explain why customers might be offered an update for software that is not specifically indicated as being affected in the Affected Software and Vulnerability Severity Ratings table. These are informational changes only. Customers who have already successfully installed the updates do not need to take any further action.
Information published.