Ok.. enough with the esotherical blabbering..

There's an actual trojan out for this now

http://www.theregister.com/2005/12/0...xploit_trojan/
http://www.microsoft.com/security/en...:Win32/Delf.DH

And still no patch..

So I'd still like to call it a vulnerability in the default installation of Windows
(except for server 2003 which has ActiveScripting disabled by default)