It's a hole in the RPC protocol. On the MS site we can find:
The protocol itself is derived from the Open Software Foundation (OSF) RPC protocol, but with the addition of some Microsoft-specific extensions.
Where is the bug ? In the MS additions ? Or all systems using such protocol is affected ?