Authentication is not required to exploit this vulnerability.
The specific flaw exists within the SMTP service while processing a malformed e-mail. The process continually appends each argument within a filename parameter into a buffer in memory. By providing enough data this buffer can overflow leading to arbitrary code execution under the context of the SYSTEM user.
Disclosure Timeline:
2008-08-26 - Vulnerability reported to vendor
2011-02-07 - Coordinated public release of advisory