That exploit is kinda worthless IMO, the attacker would still need to be able to save his .dll into a folder where Windows looks for extra .dll's. And to move files into those folders it needs Admin rights. So an attacker would kinda need to trick you into copying his evil SciLexer.dll into some folder... and who the fuck puts random .dll's from some person into some folders?