This would only be a remote exploit insofar as command line access would be a pre-requisite on the target machine for this to even be possible.... right? Or is there a devious way of issuing a regsvr32 command that I am having a brain dump on?