Newly found Vulnerabilities03/10/08:
Trojan Exploiting Microsoft Excel Vulnerability
We are aware of public reports of a Trojan that may exploit
vulnerability in Microsoft Excel. This Trojan is circulating through email
messages that contain attached Excel files. Known file names for these
attachments are OLYMPIC.XLS and SCHEDULE.XLS. These files may also contain
Windows binary executables that can compromise an affected system.
We do encourage users to do the following to help mitigate the risk:
Review
Microsoft Security Advisory 947563 for workarounds.
Do
not open unsolicited or entrusted email messages.
Use
caution when opening email attachments.
Block
executable files and unknown file types at the email gateway.
Install
anti-virus software, and keep its virus signature files up-to-date.