Microsoft have today admitted that they have received reports of a brand new
vulnerability affecting all versions of Microsoft Excel. Mike Reavey, security
program manager, posted to
the companys blog today explaining that users need to download and run a
specially crafted Excel document in order for the attack to take place.
However,
Secunia have rated the vulnerability as "Extremely Critical" which is their
highest rating as 0day code is out in the wild and the vulnerability is being
actively exploited. The vulnerability has been confirmed on a fully updated
Windows XP SP2 system with Microsoft Excel 2003 SP2. Other versions may also be
affected. Symantec are already reporting
a trojan (trojan.mdropper.j) that drops malware onto machines using the
undocumented vulnerability. Trojan.Mdropper.J may arrive as a Microsoft Excel
file attachment to a spoofed email with the following name: okN.xls