The new patch issued by Microsoft on October 4th did NOT fix the XML vulnerability correctly.
http://www.securityfocus.com/archive/1/340539
You can view the proof-of-concept on http://mindlock.bestweb.net/wmp.htm
Microsoft has not replied or issued a new patch yet.




Reply With Quote