Microsoft Security Advisory (961040)
Vulnerability in SQL Server Could Allow Remote Code Execution
In 2008, I've met 3 organizations that STILL do not have an automatic patching strategy for their SQL machines. Bad idea. If you are still patching them manually, get 'em done now, before this one bites you.