With its February security patches now two weeks away, Microsoft is warning of critical flaw in the Office spreadsheet software, Excel.
Microsoft confirmed late Friday that another vulnerability targeting the Office application had been found and said that the problem may also affect other Office software as well.
The software giant is investigating reports that the flaw is being used by criminals in "very limited," attacks, according to a Microsoft security advisory.
This latest flaw affects Microsoft Office 2000, Microsoft Office XP, Microsoft Office 2003, and Microsoft Office 2004 for Mac.
Over the past year hackers have increasingly focused on Office applications as a security hole and the attacks based on these flaws are often the same: Criminals send an email that appears legitimate, and trick unsuspecting users into opening a maliciously encoded document. Once the document is opened, attackers are able to install unauthorised software on the victim's system.
Microsoft may not have time to patch the Excel flaw in time for its next set of security updates, expected 13 February, but, no doubt, it has other Office patches in the works. Over the past few months four similarly critical flaws have been reported in Microsoft Word. None of these has yet been patched.