From the 2 articles posted it wasnt saying that it was writing into the ie processes memory, it was rewriting some dlls back to unpatched versions so that it becomes vuln again, dlls are just files...