I have published a new proof of concept tool, named "Smbrelay3",
that is
able to replay NTLM authentication from several protocols like
SMB/HTTP/IMAP/..
http://www.tarasco.org/security/smbrelay/index.html
Microsoft Device IO Control wrapped by the iphlpapi.dll API shipping with Windows Vista 32 bit and 64 bit contains a possibly exploitable, buffer overflow corrupting kernel memory.