Microsoft paused the optional KB5002907 update after reports that it deactivated legitimate perpetual-license Office 2016 and Office 2019 installations, causing applications to display “Unlicensed Product.” The update targeted systems running Microsoft 365 Apps more than 90 days behind on the Current Channel or Monthly Enterprise Channel, including some one-time-purchase Office Home & Business customers.
In rare cases, the update reportedly removed Office entirely; unconfirmed reports link failed reinstalls to systems combining 32-bit Office with 64-bit Microsoft Access Runtime. Microsoft is investigating and has halted the rollout. Affected users can try reactivating with the original product key or linked Microsoft account, while users whose Office installation was removed should download and reinstall their purchased version.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Reports surfaced that KB5002907 caused one-time-purchase Office 2016 and Office 2019 Home & Business installations to appear as unlicensed or, in some cases, be removed. Belgian MSP operator Christian Van Hautte reported five unrelated customers affecting dozens of PCs within about ten minutes; re-entering product keys restored activation on some systems.
Microsoft released KB5002907 through Windows Update for Microsoft 365 Apps installations on the Current Channel or Monthly Enterprise Channel that were more than 90 days out of date. The update was intended to let outdated installations resume updating and move to their assigned channel's current build.
Microsoft ended support for Office 2016 and Office 2019, while stating that customers could continue using the suites.
Microsoft acknowledged that KB5002907 could leave Office 2016 or Office 2019 appearing unlicensed or, rarely, remove it entirely, and paused the rollout while investigating. It advised affected customers to reactivate with their product key or linked Microsoft account, or reinstall their purchased Office copy if it was removed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.