This exploit is very critical because it will attack the client. Why the client is so danger to this vulnerability? Ok let's we make some illustration here. The bank. Bank have a very good security procedure. So it almost impossible to attack it. And let's take another way "the client" what do you think?
The question is who is the client? what they use to open the e-mail? what is their operating system? what version is it? what is the browser they use? All of this question will you get if you do the social engineering technique. So when you get that information you can use some client side exploit like this example. So, what the solution? Nothing we can do against this. All we can do is patch from the vendor. My solution here is learn some skill from bad guy world so you know how they do this and know how to prevent that. This video taken from offensive-security.