The exploit takes advantage of a memory corruption vulnerability in Excel 2002 sp3. It uses a combination of pop pop ret and call esp instructions to execute shellcode.
A vulnerability in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Excel file containing a malformed HFPicture record, as exploited in the wild in June 2010.