This is unreal... I thought these kinds of things would've been fixed in 2000 with the ILOVEYOU virus [1]. But apparently Excel VBA allows you to manipulate the registry, access Windows APIs, drop files onto the system, and manipulate/access Outlook to run macros across all of your mail and more. Does Microsoft really expect the average office worker to not fall for an urgent-looking, highly-realistic spreadsheet asking him to enable everything? If this is really what I think this is it's an obvious security disaster for the whole Windows ecosystem.