The biggest threat to security in IE is the SAME as with every other browser: installation of code that is not necessary and that goes double for exe files. I know a lot of people who will download and install executables when using IE, as if their brains just went out the window, despite IE warning them at least once, and Windows Vista/7 warning them again. AND, the same people despite being advised to use Firefox, will use IE reflexively, and even search it out, defeating the hard work of making every possible association with the web with Firefox. So, it largely comes down to idiocy on the part of the human user.
With the appropriate ad, flash, and javascript blocker add-ons, and a user who doesn't just install every damn Active X control under the sun, IE is pretty secure. But, the aforementioned idiots can take the tightest set-up VMWare virtual Windows instance, even with Firefox, and get it so infected that the infections find their way out of the sandbox onto the real world machine and LAN.
There's no replacement for simple common sense, which is now so uncommon, Deadpool has it as a super power.