Exploiting this vulnerability involves sending a specifically crafted request to a system utilizing RDP (Remote Desktop Protocol). An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. This can include installing programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability exists prior to any credential passing, potentially allowing this threat to spread in a worm-like fashion.
Vendor has released updates/ patches for the following products.
Windows XP SP3 x86, Windows XP Professional x64 Edition SP2, Windows XP Embedded SP3 x86, Windows Server 2003 SP2 x86, Windows Server 2003 x64 Edition SP2