Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Because of the vulnerability (see notes at the end of the module) DEP bypass has not been achieved.
The derefence is done against a buffer on the heap as base, and user controlled parameter as offset. The buffer on the heap is allocated along the activex initialization, and doesn't use the default heap. Because of this achieving heap feng shui doesn't seem easy. As we added a module for cve-2012-0266 too (see #812) I've added it anyway for CVE coverage. And it's an interesting vuln anyway :)