Microsoft Security Advisory (961040): Vulnerability in SQL Server Could Allow Remote Code Execution - 2/10/2009
Revision Note: V2.0 (February 10, 2009): Advisory updated to reflect publication of security bulletin. Advisory Summary:Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS09-004 to address this issue. For more information about this issue, including download links for an available security update, please review MS09-004. The vulnerability addressed is the Microsoft XML Core Services Vulnerability - CVE-2008-5416.
Here is the original:
Microsoft Security Advisory (961040): Vulnerability in SQL Server Could Allow Remote Code Execution - 2/10/2009