A new vulnerability has been found in Microsoft’s Excel spreadsheet program, just a few days after the company fixed problems with several of its applications in its monthly patch distribution.One customer reported an attack using the vulnerability, which comes from an e-mail with a malicious Excel document attached, wrote Mike Reavey, Microsoft security program manager, on the company’s security blog.The blog post did not give further details on what the malware does when downloaded. The blog post can be found here.Reavey noted that the e-mail application should prompt users to take care if they attempt to open the attachment. He cautioned against opening unsolicited documents, whomever they come from. Microsoft has updated its own Windows Live Safety Center, a Web-based antivirus and performance-improvement service now in beta release, to detect documents attempting to exploit the vulnerability, and also shared the information with security partners, Reavey wrote.“We’ve got the Office team engaged, of course, and they are hard at work investigating the vulnerability,” Reavey wrote. On Tuesday, Microsoft issued 12 updates for 21 vulnerabilities, one of the company’s largest patch handouts for applications including Internet Explorer, Outlook Express, Word, PowerPoint and Windows Media Player.Observers noted the patches affected mostly client-side applications. Of the 21 vulnerabilities, 19 could have allowed a hacker to gain remote control over a computer and possibly corrupt or steal data.— Jeremy Kirk, IDG News Service (London BureauRelated Links:• Bill Gates to Leave Day-To-Day Role in 2008 (CIO.com) • Microsoft Gives ActiveX Reprieve to Some Customers • Microsoft Patches Block Infected E-Mail Keep checking in at our Security Feed page, or subscribe via RSS, for updated news coverage. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe