Microsoft has replied that there is no real problem here.

"Microsoft has investigated these reports and is not aware of any instance in which an attacker could specifically bypass the service in email or a web browser to allow a malicious attacker access to a user's system."


Microsoft downplays XP SP2 flaw claims
http://www.vnunet.com/news/1157459