0xa000 · Windows Exploitation
SEH Overwrites: Hijacking Windows Exceptions
Windows keeps a linked list of exception handlers on the stack. Overflow into one, point it at a pop-pop-ret, trigger a fault, and control is yours — the technique Windows made famous.