Originally posted here by Tiger Shark
If I might chime in here....

JC: Yep... Theoretically you are correct... But... 99% of the time non-publicly available servers are compromised by their idiot admins/users using the server like it was a workstation... and running in the context of an administrator...

That's the point dear Mistress LeFay is trying to, quite correctly, make... in her roundabout way...
Again, if you look back to the infection rates of Code Red and Slammer, you'll see that 99% is a little high....