The May cumulative security update for Internet Explorer 6, 7, 8, 9, and 11 is available on Windows Update. Fixes 2 potentially dangerous bugs that were reported in time before they were publicly revealed. The most serious vulnerabilities relate to remote code execution if a user visits an attacker’s website. The user can then gain the same rights as the user.
Users with UAC (User Account Control) enabled are better protected against attacks. The update is on Windows Update, so you don't need to take any special action if you have automatic updates enabled. Otherwise, I recommend deploying this update as soon as possible, because the most vulnerable systems are in the time between the disclosure of the vulnerability and the installation of the security update.
The update is rated critical for Windows Client and Critical for Windows Server. For Windows 8.1 or Windows Server 2012 R2, it requires the 2919355 update installed. It is also available for Windows XP as a replacement for the 2964358 Emergency Update. However, there are no plans for another cumulative update for Windows XP.
An update to Adobe Flash Player for Internet Explorer 2938527 has also been released, which is rated as critical.
For more information, see MS14-029 and APSB14-14.