Microsoft plugs Office and Windows vulnerabilities
Microsoft during its monthly patch release has issue one update for Windows and one for Microsoft Office.
The Office update patches five separate vulnerabilities in Excel. Depending on the version of the software, the flaws are rated critical to important. The vulnerability spans Office for both Windows and Apple's OS X. It could allow an attacker to take over control of a system through the use of a specially crafted Excel spreadsheet. The users would have to manually open the file to get infected.
A sixth Office vulnerability spans a range of Office applications for Windows and again could expose the user to a remote code execution, allowing a attacker to install spyware or other malware.
The Windows flaw affects only system running Windows XP SP1 and Windows Server 2003. It could cause a privilege escalation, allowing a user with an existing login account that is configured with limited privileges to gain full control over a system.