> wthout a JIT, applications can still have arbitrary execution vulnerabilities.
Only on operating systems that allow dynamic executable code.
Only on operating systems that allow dynamic executable code.
I am refuting that statement by showing that not allowing dynamic executable code is not enough. It is irrelevant to that end that you can mitigate ROP by other means.
To the OS those are all identical scenarios, it's irrelevant what caused the arbitrary code execution to happen.