This is the conclusion of information technology analyst firm International Data Corporation (IDC), whose report, "Worldwide Spyware Forecast and Analysis 2004-2008" is available at http://www.idc.com/getdoc.jsp?containerId=32229
Although not all spyware is malicious, it can have the ability to defeat firewall security, and at its worst it can track keystrokes, scan hard drives, and change system and registry settings.
Spyware is often bundled with legitimate programs, a fact about which even some relatively savvy users are dangerously blasé. See "Spyware on My Machine? So What?" at http://www.wired.com/news/technology/0,1282,65906,00.html and "Terminating Spyware with Extreme Prejudice" at http://www.nytimes.com/2004/12/30/technology/circuits/30hard.html?8hpib