Ever read the monthly security bulletin they have to put out with the monthly security updates? They regularly need to fix issues that involve RCEs and privilege escalation flaws.
Microsoft's security model used to be so bad that their CEO had to put a stop on all ongoing development projects and launch a company wide security review project, which led to Windows XP SP2.
Google and Apple both have a better security track record than Microsoft. Exchange had been swiss cheese for decades, the last major event happening as recently as last year. We've also had security issues in Microsoft Office that could be exploited just by opening a malicious document.
Weaponized Office documents pose a large risk to organizations. From embedded active content, such as scripts and HTML code in Word and PowerPoint files to Excel macros, this is an attack vector every organization must pay attention to.
www.deepinstinct.com
How many attempts did it take them to resolve that printer-related issue a few years ago?
Microsoft is also the company that brought us Internet Explorer and ActiveX...
I do. First example that comes to me: just a few years ago, there was a flaw in RDP that allowed to remotely take over machines. I had a customer whose PC needed a complete reformat because he got compromised that way.