All supported versions of Windows, including the recently-released 8.1, are affected by at least one critical vulnerability. The one bulletin that affects IE fixed a critical vulnerability in all versions of the browser, including the new IE 11. Three other Windows bulletins are rated Important. Two other bulletins, both rated important, affect all supported versions of Microsoft Office.
Microsoft will also release their other usual monthly updates, including a new version of the Malicious Software Removal Tool and a large number of non-security updates. Curiously while many thought it likely that Redmond will be fixing a zero day bug in Windows and Office. The vulnerability is being used in zero-day attacks specifically against Office. The Patch Tuesday updates this month will not address this vulnerability.
Redmond said that only some Office users are being attacked, not users of the other products who are not running an affected version of Office.