Ahem, right. Getting back to the original question. 🙄
If your Windows environment, even in VPC, is open to the internet, it's going to be susceptible to every irritation the Windows world knows (and they are legion). I think the only thing that VPC maybe does for you is give you the benefit of the OS X firewall. But you are vulnerable to all the same security exploits that any other Windows user is.
So yes, you really should install all of those updates. 🙁 SP2 in particular does a *lot* for you, so that should be on your definite list....