A particularly serious Bulletin is MS07-046, which addresses a remote code execution vulnerability in the Graphical Device Interface (GDI), which renders graphics and formats text. Since every application uses the GDI in one way or another, every Windows user is at risk for this exploit.
Another notable fix is MS07-048, which is rated as important. It addresses a number of vulnerabilities in Vista that could allow an anonymous remote attacker to run code with the privileges of Windows user.
What's unique is the method of attack. The remote code execution could gain access to the computer through a malicious RSS feed in the Feed Headlines Gadget or by adding a malicious contacts file in the Contacts Gadget, or if a user clicked on a malicious link in the Weather Gadget.
Bulletin MS07-050, a critical fix, fixes a vulnerability in the Vector Markup Language (VML) used in Windows. The VML has seen its share of problems recently. Bulletin MS07-047 is an important fix for Windows Media Player.