Security News > 2021 > February > Microsoft Office February security updates patch Sharepoint, Excel RCE bugs

Microsoft has addressed important severity remote code execution vulnerabilities affecting multiple Office products in the January 2021 Office security updates.
Microsoft also released non-security Office updates last week addressing bugs that may lead to PowerPoint crashes and other issues affecting Windows Installer editions of Office 2016, Office 2013, and Office 2010 products.
The company issued the February 2021 Patch Tuesday updates yesterday, with patches for a Windows Win32k elevation of privilege zero-day exploited in the wild and 56 other security vulnerabilities, 11 of them classified as critical severity.
Microsoft urged customers to install security updates for three critical and high severity Windows TCP/IP security bugs as soon as possible due to the elevated exploitation risk and potential denial-of-service attacks that could soon target unpatched systems.
This month's Office security updates address bugs exposing Windows systems running vulnerable Click to Run and Microsoft Installer-based editions of Microsoft Office products to remote code execution, information disclosure, and spoofing attacks.
Microsoft Office security updates can be installed through the Microsoft Update platform or via Microsoft's Download Center.
News URL
Related news
- April 2025 Patch Tuesday forecast: More AI security introduced by Microsoft (source)
- Fake Microsoft Office add-in tools push malware via SourceForge (source)
- Week in review: Chrome sandbox escape 0-day fixed, Microsoft adds new AI agents to Security Copilot (source)
- Still Using an Older Version of iOS or iPadOS? Update Now to Patch These Critical Security Vulnerabilities (source)
- Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws (source)
- Google's got a hot cloud infosec startup, a new unified platform — and its eye on Microsoft's $20B+ security biz (source)
- Patch Tuesday: Microsoft Fixes 134 Vulnerabilities, Including 1 Zero-Day (source)
- Microsoft releases emergency update to fix Office 2016 crashes (source)
- Microsoft: Windows 'inetpub' folder created by security fix, don’t delete (source)
- Microsoft blocks ActiveX by default in Microsoft 365, Office 2024 (source)