Although the exploit is tricky to perform, it combines two vulnerabilities in Internet Explorer 6 with a series of ActiveX exploits to break security settings in computers running SP2. It runs when a user moves a file or an image from one part of a Web page to another, but in the process the exploit downloads code to machines that circumnavigates Local Computer security settings in SP2.
Researchers at Danish security company Secunia have labelled the vulnerability as "highly critical" because it allows hackers to access local resources and bypass security features in Windows XP SP2.
"This is the most serious vulnerability for SP2 that we have the moment," said Thomas Kristensen. "The problem is that by exploiting this vulnerability in IE it's possible to drag a file into the local security zone and change the settings. On an SP2 system, this shouldn't be a problem, but it is still possible to bypass the security with an Active X control."
The company pointed out that Windows XP SP2 does not run Active Scripting in the Local Computer zone, but by performing a series of Active X exploits it is possible to bypass those setting in SP2.
"It's a series of events you have to perform before you are able to bypass security settings," said Kristensen. "It is complicated. But they are several minor issues that can be compromised so it's possible to circumnavigate the security settings."
Kristensen added that SP2 was supposed to tightly lock down the security issues with IE 6, but this was clearly a compromise in it security. He said that the solution was to disable the drag-and-drop or copy-and-paste options on Internet Explorer and set the security level to "high" in the Internet zone.











Service Pack 2 is no better.
In my experience with service pack 2 I would not recomend it at all.
For starters I have been hacked through 2 firewalls within 3 days of a rebuild to go to service pack 2. The security features are a nightmare for gamers who want to tweak performance by disabling certain services and apps.
Typical Microsoft rubbish, Once agin they are not thourough in their work.
I personally dont care hiow many lines of code ther are as it is irrelavant, they just need to make it safe no matter what and not release it untill it works with feature which suit all situations.