Microsoft Security Updates Focus on Office
Schultze said that he would patch the MS08-015 update before all others. That's because, while users may now be learning to hesitate before opening untrusted Office documents, they generally don't think twice about clicking on a Web link.
"Clicking on the email link can allow the attacker to run code on your system, assuming that you have Microsoft Outlook," Schultze said. "There would be very little way to know ahead of time whether or not the mail link was evil. I expect we'll see exploit code for this very shortly."
The two other security updates fix critical flaws in Office and in the Office Web Components ActiveX controls used by products such as Office, BizTalk Server, Commerce Server, and the Internet Security and Acceleration (ISA) Server.



