Microsoft Issues Security Advisory for Zero-Day Excel Vulnerability

Microsoft Issues Security Advisory for Zero-Day Excel Vulnerability

Written By
Brian Prince
Brian Prince
Feb 24, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft has confirmed that hackers are targeting a new vulnerability that could lead to arbitrary code execution.

In an advisory, Microsoft described how the bug can be exploited using a specially crafted Excel document. The malicious Excel file attempts to access an invalid object, allowing the attacker to execute arbitrary code.

According to Microsoft, the vulnerability is currently being exploited in “limited and targeted attacks.” The advisory addresses Microsoft Office 2000, Office 2002, Office 2003, Office 2007, Office 2004 for Mac and Office 2008 for Mac.

If a user is logged on with administrative user rights, an attacker could take complete control of the affected system, gaining the ability to install programs and view, change or delete data, Microsoft warned.

“We have added detection for the malicious spreadsheet files we have seen in the wild, which will be detected as Trojan.Mdropper.AC,” said a post on Symantec‘s Security Response Blog. “The malicious binary dropped by the spreadsheet will be detected as a Trojan horse. Ensure that your definitions are up-to-date to protect yourself from the danger this issue presents.”

Microsoft recommended setting the “Microsoft Office File Block policy to block the opening of Office 2003 and earlier documents from unknown or untrusted sources and locations.” Instructions are included in the Microsoft advisory linked to above. Another workaround is to use MOICE (the Microsoft Office Isolated Conversion Environment) “when opening files from unknown or untrusted sources.” Instructions for installing MOICE are also available as part of the advisory.

There was no word from Microsoft on when a permanent fix for the issue would be forthcoming.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.