The most interesting vulnerability this month is actually in the non-critical ones: a vulnerability in Hyper-V. Were also getting a fix for a 0-day vulnerability in ActiveX (MS13-090) The next critical bulletin is for the Windows Graphical Device Interface (GDI), where a malicious embedded BMP can result in remote code execution (CVE-2013-3940) The final critical bulletin, the last, covers a vulnerability thats seeing limited exploitation in the wild.”]
Source: https://blog.talosintelligence.com/2013/11/microsoft-update-tuesday-november-2013.html

