Meanwhile, Microsoft insists that it is "only of limited and targeted attacks that attempt to use this vulnerability." It goes on to say that it is "actively working with partners" to investigate the issue and will "take the appropriate action to protect our customers" in due course.
The appropriate action being either a solution through a service pack, a monthly security update or even an out-of-cycle security update.
Microsoft gives no indication of when the investigation will be complete or when a solution might be forthcoming, however.
Let's hope it is real soon, especially when you consider that the vulnerability appears to impact all versions of Excel, and that includes back as far as MS Office 2004 as well as MS Office 2008 for the Mac.
Microsoft admits that if an attacker successfully exploits the vulnerability then they could gain the same user rights as the local user. Furthermore, that "compromised Web sites and Web sites that accept or host user-provided content could contain specially crafted content that could exploit this vulnerability."
So come on Microsoft, when are you going to resolve this and all the other outstanding Excel security issues and make MS Office a safe place to work again?