http://www.microsoft.com/technet/security/bulletin/MS03-043.asp

Buffer Overrun in Messenger Service Could Allow Code Execution (828035)

Issued: October 15, 2003

Version Number: 1.0

Summary

Who Should Read This Document: Customers using Microsoft® Windows®

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should disable the Messenger Service immediately
and evaluate their need to deploy the patch

Patch Replacement: None

Caveats: None

Tested Software and Patch Download Locations:
Affected Software:
Microsoft Windows NT Workstation 4.0, Service Pack 6a - Download the patch
Microsoft Windows NT Server 4.0, Service Pack 6a - Download the patch
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6 -
Download the patch
Microsoft Windows 2000, Service Pack 2 - Download the patch
Microsoft Windows 2000, Service Pack 3, Service Pack 4 - Download the patch
Microsoft Windows XP Gold, Service Pack 1 - Download the patch
Microsoft Windows XP 64-bit Edition - Download the patch
Microsoft Windows XP 64-bit Edition Version 2003 - Download the patch
Microsoft Windows Server 2003 - Download the patch
Microsoft Windows Server 2003 64-bit Edition - Download the patch