They will be patched. There is also no indication that they 'be been known and exploited till recently.
This was allegedly deliberately non patched to be exploited.
Getting a system without bugs and security issues is impossible, you can at least avoid intentional compromise.
Microsoft shipping a vulnerable version of the recovery environment. It is the 'exploit'.
Such is the nature of closed source software. You select people who will remain complicit till they have a grievance against you. Even if they don't and talked for moral reasons do you think they would not been fired for it?
Who knows. How many more went through at closed source software a limited amount of people can test in the same way?