Hi,
You've gotta remember that worms may not have anything to do as far as the network layer is concerned. If a worm propagates at the application layer, it does not really matter whether you are doing NAT or not e.g. if your internal machines are allowed HTTP access to the Internet, they are susceptible to worms and other security vulnerabilities that propagate through HTTP. The same applies to worms propagating through email.
So yeah, I strongly recommend that you install all relevant Microsoft patches :-)
Paresh
PS. Pls rate all posts.