Thanks to yashiro on BPN for this. :)
Researchers at GreyMagic Software have uncovered three novel vulnerabilities provided by Microsoft Office Web Components (OWC), which can override security settings in Internet Explorer.
First up, it's possible, using the spreadsheet component of OWC, to enable active scripting when the user has it disabled in IE.
"One of the features added to the spreadsheet component is the '=HOST()' formula, which returns a handle to the hosting environment.
"It is possible to use this formula in order to manipulate the DOM [the Document Object Model, which allows scripts to access and alter documents], which is a security issue in itself when Active Scripting is disabled, but it's somewhat limited because there's no way to add logic (conditions, loops, etc.) to the calls made.
"However, with a bit of manipulation it is possible to get Active Scripting to kick in. By using the setTimeout method of the window object through the '=HOST()' formula it is possible to execute script with any language available to the host," GreyMagic says.
The workaround for now is to disable not just active scripting but ActiveX and plugins as well. There is a sample script and two demonstrations linked at the bottom of the GMS bulletin here , one of which enables the curious to try out their own scripts quite conveniently.
News source: The Register