The new patch issued by Microsoft on October 4th did NOT fix the XML vulnerability correctly.

http://www.securityfocus.com/archive/1/340539


You can view the proof-of-concept on http://mindlock.bestweb.net/wmp.htm


Microsoft has not replied or issued a new patch yet.