While that developer used this power to amuse, a more disgruntled person could probably come up with pictures, or executecode, that might not be so funny.
In its security advisory, Microsoft labeled three of the bulletins "critical, " meaning an attacker could remotely execute malicious code on unpatched systems.
"An attacker can craft a malicious internet link to execute malicious code remotely on victim's system, which has Origin installed, " wrote the researchers in a paper detailing their work.
The vulnerability exists when MSXML attempts to access an object in memory that has not been initialized, which may corrupt memory in such a way that an attacker could execute arbitrary code in the context of the logged-on user.