Due to my particular interests in projects, I won't be using the BOINC client (at least not for a long time, hopefully, since if F@H were to switch over - and I doubt they will anytime soon - we would loose all our stats again, and we lost them once already in the v1 to v2 transition), but the F@H software uses an auto-updating core, is used on over 160,000 active systems, and we've not had any security vulnerabilities yet, AFAIK.
I say this not to state that this is something that should be taken lightly, but just to point out that this kind of thing is already done, and not just on a small scale, without problems (then again the Stanford guys are a bit more careful than MS seems to be, and they don't put out an update without careful testing). Of course, there will always be a paranoid few who run their "untrusted" software in a chroot sandbox, or an entirely separate VM, or don't run it at all, because of some issue, but I doubt this will be a problem for most people, assuming the BOINC guys do it as well as F@H has.