A video demonstrating how to exploit this CVE.
"riched20.dll.dll" can be coded so you don't have to call another DLL to execute your payload.
The exploit can be downloaded here :
https://gist.github.com/quentinEccE/a...
or here :
https://cxsecurity.com/issue/WLB-2016...