The recently-patched flaw could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user.
Source: Threadpost