Secunia writes (http://secunia.com/advisories/13802/):
QUOTE
Description:
A vulnerability has been reported in Microsoft Windows XP and 2003, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an unchecked buffer in the indexing service. This can be exploited to execute arbitrary code through a malicious query.

Note: This vulnerability has been set to "From Remote" because the indexing service can be configured to be accessible through Internet Information Services (IIS).

Solution:
Apply patches.


There are patches for the following, please visit the secunia url above for links to the patches:

Microsoft Windows XP (requires Service Pack 1)
Microsoft Windows XP 64-Bit Edition (requires Service Pack 1)
Microsoft Windows XP 64-Bit Edition Version 2003
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64-Bit Edition