By now you've probably seen the news about the Mac Office updates that went live on MacTopia for a few hours this past Tuesday. Things were a little crazy here on Wednesday and Thursday working out what happened and how we should resolve the problem. Since I'm the development lead for our Sustained Engineering meta-team, I thought you might like to hear what's going on directly from me. (I would have posted this earlier except that I was at home without electricity for most of Friday due to the wind storm that blew through the Seattle area Thursday night. Microsoft itself was without power in many buildings, including mine, until late Saturday afternoon.)
Since the MacBU is a relatively small team, we are often working in parallel on a number of stability and reliability issues with the older supported versions of Mac Office, as well as any security issues that we find or that are referred to us by external people or Microsoft's own security teams. Each of the fixes we are working on needs to be tested individually and in conjunction with each other, plus we test the patch installer itself. Beyond that, we need to test the actual download process to make sure we've got the right URLs in place, that the right bits are up on the server, etc. On Tuesday, while testing that download process for an upcoming Office patch, we accidentally released the bits to the live servers. That patch included some normal stability issues as well as preparatory work for an upcoming security release. All the code in the patch had been tested and approved except for the security-related bits, which we weren't ready to release. Even though we removed the patch pretty quickly, a small number of our users downloaded the patch during the time it was live.
The MSRC team put up a notice on their blog. That post told users to uninstall the patch without giving clear guidance on how to do that. Unfortunately, there is no easy way to uninstall it without going back to the original CD and doing a clean install followed by applying the latest full updater. That's a really poor user experience for those who installed the
update, so the MacBU is working very quickly to rectify the situation. As it turns out, however, the code that went live has no known issues, so while we recalled it because it had not been thoroughly vetted, there's no urgent need to uninstall the patch.
MacBU will very shortly provide a new updater for both Office X (version 10.1.9, with a new build number) and 2004 (version 11.3.2) that contains all of the stability improvements that were ready to go live, and removes the not-yet-ready-for-prime-time code that was accidentally released. These updaters will be available in Microsoft AutoUpdate as well as on MacTopia, and should be online in the near future, hopefully by the end of this coming week. The MSRC has since posted a new notice with this information as well.
I do want to reiterate that the security issue mentioned is not related to the Word zero-day alert that Microsoft warned about recently. I'm sorry for the confusion that resulted, both from the publishing and subsequent quick removal of the patch, and from the incomplete uninstall instructions and delay in more precise information from MacBU. It took us most of Wednesday and Thursday to get a plan in place and verify that we can indeed pull it off quickly, especially with the need to coordinate with our teams in Ireland and Japan to do localized patches in time.
If you really want to uninstall the patch (again, you do not need to do so), there are very complete instructions on the Word MVP site, or you can follow these abbreviated steps:
- Move the Microsoft Office 2004 or X folder to the trash (make sure you keep any important templates or other documents you may have saved into this folder)
- Empty the trash
- Reboot your Mac to ensure that the Entourage Database Daemon is not running (or use unix commands to terminate the process from the Terminal)
- Re-install Office from your original CD (drag-and-drop is fine)
- Run Microsoft AutoUpdate to re-install the 11.3.0 update. (For Office X, you'll need to download and install the 10.1.8 patch manually)
So, stay tuned for a replacement update coming your way soon!