Fix for Excel zero-day may be coming from Microsoft

Microsoft on Tuesday plans to ship eight security fixes as part of its monthly release cycle.

Five of the bulletins address "critical" flaws, two address "important" bugs and one addresses a "moderate" flaw, according to an advance notification bulletin. Of the five critical patches, three involve Windows issues, one affects Internet Explorer and the other involves Excel.

In late February, Microsoft announced that a vulnerability in Excel was being exploited in targeted attacks. However, Microsoft will not reveal which hole the Excel fix -- which affects Office 2000, XP, 2003, 2007 and Office for Mac versions -- plugs prior to Tuesday's release.

The patches labeled important fix flaws in Windows and Microsoft Internet Security & Acceleration Server (ISA), while the moderate patch addresses at least one more bug in Windows.

The update is expected to be released around 2 p.m. EST Tuesday and will include, as always, the latest Malicious Software Removal Tool.








More in News

Privacy-bolstering "Apps Act" introduced in House

The bill would provide consumers nationwide with similar protections already enforced by a California law.

Microsoft readies permanent fix for Internet Explorer bug used in energy attacks

Microsoft is prepping a whopper of a security update that will close 33 vulnerabilities, likely including an Internet Explorer (IE) flaw that has been used in targeted website attacks against the U.S. government.

Weakness in Adobe ColdFusion allowed court hackers access to 160K SSNs

Up to 160,000 Social Security numbers and one million driver's license numbers may have been accessed by intruders.