TLDR: Its done with Flash. Quelle Surprise.
Disabling the Flash plugin within IE will prevent the exploit from functioning.
Disabling the Flash plugin within IE will prevent the exploit from functioning.
The exploit leverages a previously unknown use-after-free vulnerability, and uses a well-known Flash exploitation technique to achieve arbitrary memory access and bypass Windows’ ASLR and DEP protections.
...
The SWF file calls back to Javascript in IE to trigger the IE bug and overwrite the length field of a Flash vector object in the heapspray.