In an advisory, Microsoft confirmed a new wave of limited “zero-day” attacks was underway, using a code execution flaw in its Microsoft Office desktop productivity suite. Although .xls files are currently being used to launch the spear phishing attacks, Microsoft said users of other Office applications (Word, PowerPoint, Outlook, Access, etc.) are potentially at risk.
Users of Office 2007 are deemed safe, but users of all previous versions back to Office 2000 should use caution when receiving Excel files. Mac users should use caution also, since Office 2004 X is not exempt from the attack either.
Source: ZD Net