This item ensures that an update of the Mixed Mode domain attribute on a domain object occurs only until all your domain controllers (DC) are running Windows .NET Server. This ensures that a Windows 2000 domain controller does not get notified to make an inexpensive search and possibly block authentications to it.
Note This vulnerability only affects your existing domain when you add a .NET domain controller to it. A .NET domain by itself is not affected by this vulnerability.