On 21 December 2004, several months after discovering one of the flaws, an independent US computer security team called GreyHats Security Group published code showing exactly how to use the flaw to hijack a computer.
Microsoft has yet to release a software fix for any of the problems and US computer security firm Secunia raised its threat assessment for all three flaws to the most severe on Friday....
...A statement posted to GreyHats Security Group's website defends the decision to post the example code online, on the grounds that Microsoft was alerted to the problem in October 2004.
"Think of how irresponsible it was of Microsoft to not patch these vulnerabilities during the several months that they were known," says a statement from GreyHats. "It would have been easy to fix some of the core vulnerabilities."
http://www.newscientist.com/article.ns?id=dn6862