如何在无互联网连接的Windows Server 2019上手动更新Microsoft Office 2021以修复指定CVE漏洞
Hey there, I’ve dealt with similar offline Office update scenarios before, so let’s walk through this step by step to get those CVEs patched properly.
First, the key challenge here is mapping your listed CVEs to the correct update packages, then getting those files onto your offline server. Let’s break it down:
1. Identify the Exact Updates You Need
Your Office 2021 is on Version 2304 (Build 16327.20214), so we need to find the updates that address each CVE and are compatible with this base build. Here’s the breakdown:
Outlook 2021 Fixes
- CVE-2023-36568 & CVE-2023-36413: Fixed in KB5002457 (July 2023 cumulative update)
- CVE-2024-20677: Fixed in KB5002524 (January 2024 cumulative update)
Excel 2021 Fixes
- CVE-2023-24953, CVE-2023-33162 & CVE-2023-33161: Fixed in KB5002234 (May 2023 cumulative update)
Word 2021 Fixes
- CVE-2023-36009: Fixed in KB5002458 (July 2023 cumulative update)
- CVE-2024-21379: Fixed in KB5002525 (January 2024 cumulative update)
Important: These updates need to be installed in chronological order (May → July → January) since later updates may depend on earlier ones.
2. Download Updates on an Internet-Connected Machine
You have two options here, depending on whether your Office 2021 is installed via MSI or Click-to-Run:
Option A: Individual KB Installers (MSI-Based Office)
- On a machine with internet, search for each KB number plus "Office 2021" to locate the correct installer (usually a
.exeor.msufile) matching your system architecture (32-bit or 64-bit). - Save all the installers to a folder you can easily transfer later.
Option B: Office Deployment Tool (ODT) for Click-to-Run Office
This is more efficient if you need to apply multiple updates at once:
- Download the ODT executable (a small tool) on an internet-connected machine, then run it to extract
setup.exeand sample configuration files. - Create a custom
config.xmlfile with the following content (adjust language and architecture as needed):<Configuration> <Add OfficeClientEdition="64" Channel="PerpetualVL2021"> <Product ID="ProPlus2021Volume"> <Language ID="en-us" /> </Product> </Add> <Updates Enabled="TRUE" UpdatePath="C:\OfficeOfflineUpdates" /> <Display Level="None" AcceptEULA="TRUE" /> </Configuration> - Open Command Prompt as admin, navigate to the ODT folder, and run:
This will download all necessary update files to thesetup.exe /download config.xmlC:\OfficeOfflineUpdatesdirectory.
3. Transfer Files to the Offline Server
Use a USB drive, local network share, or any offline transfer method to copy the downloaded installers (either individual KBs or the ODT update folder) to your Windows Server 2019 machine.
4. Install the Updates
For MSI-Based Office
- Run each KB installer as an administrator, following the chronological order (May 2023 → July 2023 → January 2024). Wait for each installation to complete before moving to the next.
For Click-to-Run Office
- Copy the ODT
setup.exeand your customconfig.xmlto the server (alongside the update folder). - Open Command Prompt as admin, navigate to the folder with these files, and run:
This will silently apply all the updates in one batch.setup.exe /configure config.xml
5. Verify the Fixes
- Open each Office app (Outlook, Excel, Word), go to File → Account → About [App] to check the build number. It should be updated to at least the January 2024 build (e.g., 16.0.16731.20170 or later).
- Alternatively, run
wmic qfe listin Command Prompt to confirm that all the listed KBs appear in the installed updates list.
Quick Tips
- Always back up your server before applying updates, especially for critical production systems.
- To check if you have MSI or Click-to-Run Office: Open any app, go to File → Account. If you see "Update Options" listed, it’s Click-to-Run; if not, it’s MSI.
备注:内容来源于stack exchange,提问作者sjarasan

