Microsoft's Excel spreadsheet program has a zero-day vulnerability that attackers are exploiting on the Internet Microsoft’s Excel spreadsheet program has a zero-day vulnerability that attackers are exploiting on the Internet.A zero-day vulnerability is one that does not have a patch and is actively being used to attack computers when it is publicly revealed. Microsoft said Tuesday that it plans to patch the issue, but did not say when. The company’s next set of security patches are set to be released March 9.“At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability,” wrote Microsoft Spokesman Bill Sisk in a blog posting. “We are developing a security update for Microsoft Office that addresses this vulnerability.”The vulnerability affects Microsoft Office 2007, Microsoft Office 2003, Microsoft Office 2002, and Microsoft Office 2000. It also affects the following Mac products: Microsoft Office 2008, Microsoft Office 2004, and the Mac’s Open XML File Format Converter. It was first disclosed Monday in an advisory posted on SecurityFocus, a Symantec-run Web site that tracks software flaws.The program’s vulnerability can be exploited if a user opens a maliciously-crafted Excel file. Then, a hacker could run unauthorized code. Symantec has detected that the exploit can leave a Trojan horse on the infected system, which it calls “Trojan.Mdropper.AC.” That Trojan, which works on PCs running the Vista and XP operating systems, is capable of downloading other malware to the computer.Like another zero-day bug in Adobe’s Reader and Acrobat software, this flaw is being exploited in dozens of targeted attacks, where victims are sent specially crafted messages tailored to make them open the malicious document, according to Vincent Weafer, vice president of Symantec Security Reponse. “We’re seeing a lot of them come around different Asian government or industries or defense contractors,” he said.Hackers have increasingly sought to find vulnerabilities in applications as Microsoft has spent much effort into making its Vista OS more secure. Related content feature Top cybersecurity M&A deals for 2023 Fears of recession, rising interest rates, mass tech layoffs, and conservative spending trends are likely to make dealmakers cautious, but an ever-increasing need to defend against bigger and faster attacks will likely keep M&A activity steady in By CSO Staff Sep 22, 2023 24 mins Mergers and Acquisitions Mergers and Acquisitions Mergers and Acquisitions brandpost Unmasking ransomware threat clusters: Why it matters to defenders Similar patterns of behavior among ransomware treat groups can help security teams better understand and prepare for attacks By Joan Goodchild Sep 21, 2023 3 mins Cybercrime news analysis China’s offensive cyber operations support “soft power” agenda in Africa Researchers track Chinese cyber espionage intrusions targeting African industrial sectors. By Michael Hill Sep 21, 2023 5 mins Advanced Persistent Threats Cyberattacks Critical Infrastructure brandpost Proactive OT security requires visibility + prevention You cannot protect your operation by simply watching and waiting. It is essential to have a defense-in-depth approach. By Austen Byers Sep 21, 2023 4 mins Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe