A vulnerability has been reported in Microsoft Windows in the Remote Desktop Protocol (RDP) implementation, allowing a remote user to cause denial of service conditions. This is of particular interest to users of XPMCE as RDP is turned on by default in that version of Windows (but not in XP Professional or Home).
No fix is available at the moment although Microsoft plan to issue a fix, presumably in August's round of fixes and patches unless the vulnerability proves to be critical.
This vulnerability could not be used to take control of a computer or network.
For the full Microsoft report
click here.
Source : MediaCenterPcWorld