Microsoft have released further details under Security Bulletin MS04-004.
Something to bear in mind, after the patch is installed, Internet Explorer no longer supports the handling of user names and passwords embedded in URLs using the "@" symbol. Not a real problem really, pretty much every website these days uses form based logins.
Full details are available in the security bulletin.
Updated On: 04.07.14