So, it is about time for the LINUX desktop!
At least every position dealing with external data hast to run a sober OS (Linux, xBSD).
Attacks such as this are IMPOSSIBLE under Linux or BSD, at least as long as you adhere to best practice (least privilege and the like).