Clarification by GreyMagic software on the recent misconception that MS03-040 patched a problem that actually lies in Jelmer’s ADODB.Stream vulnerability that gets utilized via Liu’s file:javascript vulnerability, in conjunction with another vulnerability to allow a res:// URL to open that is also by Jelmer.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31796/xmlclarity.txt
Source: https://packetstormsecurity.com/files/31796/xmlclarity.txt.html

