Exploiting the flaw would entail the creation of a maliciously malformed MIDI file, which vulnerable Windows users would have to be tricked into running, either through e-mail or a Web page
why not use MIDI files ...theres always a patch for a flaw

http://www.microsoft.com/technet/tre...n/MS03-031.asp