"'This stuff just takes a knife to a large part of the security mesh Microsoft built into Vista,' said Dai Zovi to SearchSecurity.com. 'If you think about the fact that .NET loads DLLs into the browser itself and then Microsoft assumes they're safe because they're .NET objects, you see that Microsoft didn't think about the idea that these could be used as stepping stones for other attacks. This is a real tour de force.'"
Oops, they did it again. When you read this, it seems amazing that no one discovered this huge gaping hole sooner.