Microsoft October Patch Tuesday addresses the CVE-2017-11826 Office Zero-Day vulnerability that has been exploited in the wild in targeted attacks. A remote attacker can exploit the vulnerability to execute arbitrary code by tricking victims into opening a specially crafted file. The vulnerability was spotted by researchers at China-based security firm Qihoo 360 who confirmed to have observed for the first time an attack exploiting this flaw on September 28. Attacks using office zero-day vulnerabilities targeting common users have been increasing since the beginning of 2017.”]
Source: https://securityaffairs.co/wordpress/64163/hacking/cve-2017-11826-office-zero-day.html

