
Ben Greenbaum, a senior research manager at Symantec, said that it was important that Microsoft got around to fixing the XML Core Services vulnerability because it was possible for a hacker to exploit over the Internet.
So far the flaw has not been exploited, quite why is probably because it is not so susceptible to wormable code. However security experts are at a loss as to why hackers had not exploited the bug.
Neither did Microsoft apparently. The company pinned the bug with its second-highest ranking: 'inconsistent exploit code likely'.
So if it was that important, why did it take Microsoft two years to come up with a fix?