I understand that, but, unless you've been asleep for the last 10 years, most every home user running Windows is running as a local admin, not to mention all the small businesses that are also running as either a domain admin or a local admin on a workstation.
You can try and keep running in circles, but, under a default installation, Windows users are local admins and the Windows firewall provides little hope of protection - even AOL installs punch exceptions into it without the user knowing about it.
Because they will have problems running applications as limited users - QuickBooks, POGO games, some reporting tools, many online FPS games...
The simple fact is that as long as Microsoft installs with users as admins, with the inability to run common apps unless an administrator level account, etc... users are going to be exposed to all sorts of threats.
Windows Firewall COULD have been a proper firewall, blocking in/outbound PORTS, ignoring applications, and providing a real-time interface to show traffic, but, as it is, it fails to protect user at anything other than a very basic level, and is less protection than most of the major PFW solutions on the market.
It's not luck, it's knowing the threat base and how to minimize exposure. Only those that don't understand the OS and Security would assume Luck to protect them.