Microsofts final update for the year brings us 11 bulletins covering 24 CVE issues. IE, GDI+, Office 365 and ASPNET all have bulletins marked as critical. MS13-099 covers a use-after-free vulnerability (CVE-2013-5056) in Microsoft’s Scripting Runtime Object Library, which could lead to remote code execution. The bulletin also covers 2 more vulnerabilities in the scripting runtime, which can also be triggered through IE. Microsoft has a blog post describing the fix here describing the fixes.”]
Source: https://blog.talosintelligence.com/2013/12/microsoft-update-tuesday-december-2013.html

