-
New Excel 0day
This hasn’t yet hit the main news feeds, but Microsoft just released Security Bulletin 968272, which discusses another 0day that takes advantage of a security hole in all modern versions of Excel, and the Excel Viewer.
Yes, you read that right. The Excel Viewer is vulnerable too.
Microsoft’s suggested fix for the moment? “Do not open or save Office files that you receive from un-trusted sources or that are received unexpectedly from trusted sources. This vulnerability could be exploited when a user opens a file.”
The Security Bulletin goes on to give a lengthy set of manual instructions, which includes editing the Registry, that may or may not fend off the worm. Or you can block opening files from Office 2003 or earlier.
Oh boy. In other words, bend over and kiss your keester goodbye.
Symantec has encountered an infected file, Trojan.Mdropper.AC, that’s easy to block. It remains to be seen if the exploit folks are smart and fast enough to morph the Trojan so it isn’t so easy to thwart.
Today would be a very good day to avoid opening any Excel file that you don’t know well.