Vulnerability Possible Bot Target
If you don't install the patch, you risk a remote attack running with system-level privileges, meaning the level of compromise could be severe. Of course, the attack doesn't have to be carried out remotely; tricking you into opening an attachment or downloading a file from a website is also a possibility. (See "Here's the Rub" for a recent greeting card ruse designed to trick users into installing a variant of the Haxdoor Trojan).
Common sense and safe computing habits will go a long way towards protecting you from exploited vulnerabilities, malicious software, and Internet-related attacks. Keep your patches up-to-date, use a firewall, keep your antivirus up-to-date, avoid anonymous P2P filesharing, don't open email attachments received unexpectedly, and don't click links in email sent by strangers.
Resource links:Microsoft Security Bulletin MS06-040 Vulnerability Note VU#650769 (US-CERT) MS06-040: BOLO (Sans Diary) MS06-040 attack information (Microsoft) IRC-Mocbot!MS06-040 Description(McAfee)


Mini-remark: You forgot to mention using AUTOMATIC UPDATES from Microsoft …
If one has it/them(we run WinXP so we have them turned ON) the Microsoft patch mentioned should already be on your PC. It’s on ours! We checked . . .
We love Auto Update now that we have hi-speed, full time connectivity (we also have a router (hard firewall) a software firewall, AntiVir and SpyBot and really use them all. Also Norton Utilities.)
Great work you do, BTW, we rely heavily on this newsletter!