As much as I loathe m$, the one thing they got right was forcing casual users (windows home) to install security updates as top priority, whether they like it or not. I know we all hate on windows, and rightly so, but that policy does nullify this particular vector and that is great for the consumer-level users.
(... for the sake of argument lets just pretend windows doesnt have 10,000 other vulns the malware devs can just exploit instead)