Fix it now
Windows killed the Office process because a memory safety check failed inside it: 0xc0000374 is the heap manager finding its own structures corrupted, 0xc0000409 is a detected stack buffer overrun. The module named in the crash record is usually a victim, not the culprit, so find the culprit by removing components until the crash stops.
excel /safe
winword /safe
outlook /safe
- If the application is stable in safe mode, the fault is in something safe mode did not load, and that is nearly always a COM add-in.
- Open the crashing application normally, go to File then Options then Add-ins, set Manage to COM Add-ins and Go, and clear every tick. Confirm the crash has gone.
- Re-enable half the add-ins and test, then half of whichever half brings the crash back. Four restarts finds one bad add-in among sixteen.
- If safe mode also crashes, turn off hardware graphics acceleration in File, Options, Advanced, and install the display driver from the hardware vendor.
- If the crashes follow printing or page setup, set the default printer to Microsoft Print to PDF while you test.
- If none of that changes anything, repair the installation from Settings, Apps, Installed apps, your Office entry, Modify, then Online Repair.
Note the faulting module in the Event ID 1000 record, but do not act on it. Microsoft’s own guidance is that ntdll.dll, kernel32.dll and kernelbase.dll are frequently named as victims of corruption done earlier by another module.
If the application now survives the work that used to kill it, you are done. If not, the next section explains why the crash record cannot tell you who did the damage.
Why it happens
These are not ordinary errors. They are Windows deciding that the process has been damaged badly enough that continuing is unsafe, and terminating it without giving the application a chance to save anything. Microsoft publishes 0xc0000374 as STATUS_HEAP_CORRUPTION, the structure of the heap is corrupted, with the note that this condition can cause unpredictable behaviour. 0xc0000409 is STATUS_STACK_BUFFER_OVERRUN, a detected stack buffer overrun, described as often being a precursor to a memory corruption vulnerability.
A process gets one heap and shares it between everything running inside it, Office code and add-in code alike. When a component writes past the end of a block it allocated, it overwrites the heap manager’s bookkeeping for the block next door. Nothing happens at that moment. The failure arrives later, when some entirely unrelated code allocates or frees memory and the heap manager finds the structure it depends on is nonsense. That is when the process is killed, and the module named in the event is whichever one happened to be making that call.
That is not a theory about crash records; it is what Microsoft’s own application crash guidance says. Its wording is that modules such as ntdll.dll, kernel32.dll and kernelbase.dll are frequently caught as victims of corruption previously performed by misbehaving modules, because they are so heavily used. Reading the faulting module and going to that vendor is the commonest way to waste a day on this, and it is why the steps above are a bisection rather than a checklist.
A COM add-in is corrupting the process
You have this one if Safe mode is stable. The crash returns as soon as a normal start loads the add-in set.
- Disable every COM add-in, confirm stability, then re-enable half and test. Repeat on whichever half brings the crash back.
- Include add-ins registered for all users, not only your own. Both lists load at startup.
- Where an update to the add-in exists, apply it before spending more time bisecting. Heap corruption bugs in add-ins are usually already known to the vendor.
- Report the finding with the exception code and the Office build. This class of fault is the add-in vendor’s to fix.
Bisect in halves. One at a time can take sixteen restarts, and people give up before they get there.
Graphics acceleration or the display driver
You have this one if Crashes cluster around drawing: scrolling, switching sheets, opening a chart, resizing the window.
- Turn off hardware graphics acceleration in File, Options, Advanced.
- Install the display driver from the hardware vendor rather than a generic one, and reboot.
- On virtual desktops and remote sessions, treat the remote display driver the same way.
A print driver is corrupting the process
You have this one if The crash follows printing, print preview or page setup, and changing the default printer stops it.
- Change the default printer and turn off the option that lets Windows manage it.
- Remove the suspect queue and its driver, then install the current driver from the manufacturer.
- Where the queue is shared from a server, install the driver locally and connect the device by its own port to test.
Something is injected into every process
You have this one if Several unrelated applications crash the same way, and the estate started doing it after a new agent was rolled out.
- Ask your security team whether the product injects a module into user processes, and whether a newer build exists.
- Test with protection paused, in a controlled way and with approval. If the crash stops, the vendor has its evidence.
- Do not leave protection off as a workaround. Get a fixed build.
The installation itself is damaged
You have this one if Safe mode also crashes, several Office applications fail identically, or the machine has a history of interrupted updates.
- Run an online repair from Settings, Apps, Installed apps, your Office entry, then Modify.
- Afterwards confirm from File, Account, Update Options that the product is updating cleanly.
- Where an older Office was upgraded in place and left components behind, remove the remnants with the vendor’s own removal tooling rather than by hand.
Full reference
What each code is telling you
| Code | Published meaning | What it implies for diagnosis |
|---|---|---|
0xc0000374 |
The structure of the heap is corrupted | Damage was done earlier by code that has already moved on |
0xc0000409 |
A stack buffer overrun was detected | A function wrote past a local buffer and the check at its end caught it |
0xc0000417 |
An invalid parameter was passed to a C runtime function | The runtime refused the call rather than acting on bad input |
0xc000041d |
A fatal exception was thrown inside a user callback function | An exception escaped a callback the system had invoked |
0xc0000602 |
Not published by Microsoft | Treat it as the same class of abrupt termination and bisect the same way |
None of the five names a culprit. Three of them name the moment the damage was noticed. That is the whole reason this article is structured around removing components rather than around reading logs.
Where to aim the search
| Pattern | Most likely source |
|---|---|
| Safe mode is stable, normal mode is not | A COM add-in |
| Crash on scrolling, redraw or opening a chart | The display driver or hardware graphics acceleration |
| Crash on print, print preview or page setup | The print driver |
| Crashes across several unrelated applications | A driver or an agent injected into every process |
| One document reproduces it and others do not | Content in that file, not the installation |
| Every Office application, and safe mode too | The installation, or something loaded into every process |
Page heap, and when it is worth it
If you have to hand a vendor evidence rather than a story, Microsoft’s documented tool for heap corruption is the page heap flag in GFlags. It makes the heap manager fail at the moment of the bad write rather than at the next unrelated allocation, which is what turns an unreadable dump into a useful one.
| Command | Effect |
|---|---|
Gflags.exe /i excel.exe +hpa |
Enables page heap for that image name |
Gflags.exe /i excel.exe -hpa |
Turns it off again |
Page heap slows the target application considerably and increases its memory use. Microsoft’s instruction is to restart the process for the setting to take effect and to turn the flag off once the investigation is complete. Enable it for one image, on one machine, and set yourself a reminder to remove it.
When every common cause is ruled out
- Check whether the crash follows the user or the machine. Sign the same user in elsewhere, and sign a different user in here. That one test separates a profile problem from a machine problem in ten minutes.
- Run the Windows memory diagnostic overnight. Failing memory is an uncommon cause but a cheap one to rule out, and it explains crashes that follow no pattern at all.
- If one document reproduces it and others do not, the fault is in that file’s content. Copy the content into a new file in stages rather than repairing the old one.
- Check whether the add-in set is being restored by policy or by a management tool at every start. A bisection that keeps resetting itself looks like a random crash.
- Look for shell extensions as well as Office add-ins where the crash happens around file open and save dialogues rather than inside the document.
What not to do
- Do not reinstall Windows. Nothing about these codes points at the operating system, and you will still have the add-in afterwards.
- Do not disable the memory checks. They are not the fault; they are the thing that stopped a corrupted process from writing to your files.
- Do not chase the faulting module. Microsoft says plainly that it is usually a victim.
- Do not collect more crash dumps hoping for a pattern. A dump of a corruption crash shows the moment the damage was noticed, not the moment it was caused.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0xc0000374 |
STATUS_HEAP_CORRUPTION: the structure of the heap is corrupted, and behaviour after that point is unpredictable | Microsoft Learn |
0xc0000409 |
STATUS_STACK_BUFFER_OVERRUN: a stack buffer overrun was detected, often a precursor to a memory corruption vulnerability | Microsoft Learn |
0xc000041d |
STATUS_FATAL_USER_CALLBACK_EXCEPTION: a fatal exception was thrown inside a user callback function | Microsoft Learn |
0xc0000602 |
Seen in the same Event ID 1000 crash records as the codes above. Microsoft publishes no meaning for it, so diagnose it by bisection rather than by the number | not published by the vendor |
0xc0000417 |
STATUS_INVALID_CRUNTIME_PARAMETER: an invalid parameter was passed to a C runtime function | Microsoft Learn |
Confirm the fix worked
- Repeat the action that used to crash at least three times, in a normally started application with the add-ins you intend to keep loaded.
- Confirm no new Event ID 1000 with these exception codes has appeared in the Application log since the change.
- Print, scroll and open a chart or a large document, so you exercise the drawing and printing paths as well as the one that failed.
- If you enabled page heap, confirm you have turned it off again.
- Leave the machine in normal use for a working day and check the log once more before calling it fixed.
Questions people ask about this
Is my Office or Windows licence involved in this?
No, and nothing here costs money. These codes are memory safety checks inside the running process. Activation state has no bearing on them, and no licence changes what an add-in does to the heap.
Should I collect a crash dump?
Only if a vendor has asked for one, and then enable page heap first. A plain dump of a corruption crash shows the moment the damage was noticed, not the moment it was caused, so it is far less useful than knowing which add-in has to be present for the crash to happen.
Could this be failing memory in the machine?
It is possible but uncommon, and it is cheap to rule out. Run the built-in Windows memory diagnostic overnight. If it comes back clean, spend your time on the bisection instead.
Does an online repair lose my settings or documents?
It does not touch documents. It replaces the program files and can reset some application settings, and it needs the account the product was activated with plus a working connection. Do it when you have time rather than mid-deadline.
Why does the same file crash on one PC and not another?
Because the crash needs both the content and the component that mishandles it. A document that triggers a bug in one add-in is harmless on a machine that does not have that add-in installed.
