The device running the VPN is still exposed to the attacker-controlled device. Now, on a decently-configured system this is probably fine (your workstation doesn't allow password-based SSH, right?), but it's still not great.
Network security is unmaintaniable. Start caring about defensible boundaries instead.
Also, I really do question the premise; it is possible to be selective with what you let on your network. You shouldn't rely on it, of course, but again, better to minimize exposure.