I don't know for sure if it is as prone...but PWS is just a cut down version of IIS so I would assume it is. PWS allows you to host (I think) 3 websites and and limits the number of connections (I think it is limited to 100...but that's not much...each jpeg, each text page is 1 connection/item so 100 connections is used up pretty fast).
If it's for internal testing, I wouldn't worry about it and let the clients virus software do the work. If it is being used to allow access from the public domain, I would rethink that.