Risk: High
Microsoft identifies five critical and four important flaws in April's Patch Tuesday.
The critical flaws, which may all result in remote code execution, reside in Microsoft Project, GDI, ActiveX, VBScript and JScript scripting engines in Windows and in a privately reported vulnerability that may be exploited if a user views a specially crafted web page using Internet Explorer.
The first important flaw is a spoofing vulnerability and has been identified in DNS Client, the second is in the Windows Kernel, which if exploited may lead to elevation of privilege and the third has been identified in Microsoft Office Visio, which may lead to Remote Code Execution if successfully exploited.