Mega Patch Day Includes ‘Critical’ Excel Update

A mega update for the widely used Excel spreadsheet program is the highlight of the latest batch of security patches issued by Microsoft on July 11.

One month after confirming that maliciously rigged Excel files were being used in targeted zero day attacks against businesses, Microsoft released a “critical” bulletin with patches for eight distinctly different Excel vulnerabilities.

The MS06-037 bulletin covers a wide range of “remote code execution” flaws that could let hackers take “complete control of the vulnerable client workstation.”

“We recommend that customers apply the update immediately,” Microsoft said.

Affected software packages include Office 2003 (SP1 and SP2), Office XP (SP3), Office 2000 SP3, Office 2004 for Mac and Excel v. X for Mac.

The Excel bulletin replaces the MS06-012 update issued in March 2006 to correct two more flaws in the way Office handles PNG and GIF image files.

Read the full story on eWEEK.com: Mega Patch Day Includes ‘Critical’ Excel Update