ZERT: VML, ANI and Third-party Patches

Gadi Evron and Gil Dabah

ZERT, the Zeroday Emergency Response Team, hit the news in the past 2 years with third-party patches to 0day attacks such as VML and ANI. What's behind these vulnerabilities, and how were the patches constracted?