I was reading through this fascinating thread again, especially posts that I missed earlier, when I was reminded of the time getting hit by the MS blaster worm in the early 2000's after a fresh install of XP, before the service pack that enabled the inbuilt firewall by default. My ISP only provided me a high speed cable modem, no router combo, and I didn't own a router yet. It couldn't have been more than two minutes after the install completed when the h/drive was thrashing wildly, then I saw the worm running in Task manager.
How about this being even worse than a drive-by download!? It wasn't even necessary to browse to a website to get hit by this worm and of course no user action required whatsoever.