TheFu pretty much covered it.

A VM is as safe or as vulnerable as a physical machine. Lock it down if you want to limit the risk.