Websense Security Labs has discovered a high-risk, zero-day vulnerability (MS08-014) within Microsoft Office Excel.
According to Websense, the vulnerability requires minimal user interaction. Exploit code can be embedded within Microsoft Excel files and launched upon opening an Excel document. This code could be launched over email, through a Web site, or another less common method.
Upon discovery Websense disclosed this vulnerability to Microsoft. The vulnerabilty has been patched. Because several targeted attacks have used Microsoft Office vulnerabilities, Websense recommends users to patch their machines.
According to the company, Websense ThreatSeeker technology is actively searching for in-the-wild exploits.