I'm not defending his actions, but I think he's arguing that it's likely that black-hats already know about the vulnerability because it occurs in a heavily targeted attack vector. Therefor, releasing details gives IT professionals the knowledge they need to setup firewalls or do whatever they have to do to protect against the vulnerability while waiting for an official patch from Microsoft.
With that said, perhaps there's a better way to accomplish that goal.
Furthermore, MS stated that the provided workaround is insufficient and easily circumvented.
And, he provides no evidence that any blackhats know about this at all.
To me this clearly looked like a way for Google to try to attack MS's security -- this goes hand in hand with their PR stunt of moving Google employees off of Windows due to security.
How prevalent is deploying workarounds and mitigations versus deploying patches? I don't know of any research in this area; it would be very interesting to know.
Now, take it a step further and now you have an exploit where is no Windows Update package, but each server has to be manually updated following a procedure from a webpage.
This is a no-brainer to me. Of course if you're looking for double-blind randomized control studies to prove this, well I'm afraid you're in the wrong field.