PoC for MS10-071

Here is a PoC for MS10-071
Its nice vulnerability that allows for information disclosure and triggering a use-after-free. The PoC should be able to fetch the address for mshtml.dll and then trigger a use-after-free ending the execution at eip 0x41414141 or referencing a vftable at 0x41414141 I forgot what it did.
Anyways, no explanations only the source of the PoC.

PoC: ms10-071.txt

