The FBI does not seem to be entirely convinced by Microsoft's patch. The words that they use are kind of waffling ("For additional security if you are not using the UPnP service, disable it with the following steps.") The warning is posted here:
<a href="http://www.nipc.gov/warnings/advisories/2001/01-030-2.htm" target="_blank">http://www.nipc.gov/warnings/advisories/2001/01-030-2.htm</a>
It includes the procedure for disabling Universal Plug and Play (which is not the same thing as Plug and Play).