From MS
This is addressed in the “readme.html” file in the “Help” directory under the “#firewall” section. If you require remote scanning of Windows XP Service Pack 2 machines, these conditions must be met :
• The Server service, Remote Registry service, and File & Print Sharing services must be enabled.
• Remote machine scans are performed using TCP ports 139 and 445. In a multi-domain environment, where a firewall or filtering router separates the two networks, TCP ports 139 and 445 and UDP ports 137 and 138 must be open in order for MBSA to connect and authenticate to the remote network being scanned. You must allow these ports on the remote Windows Firewall.