Many comment threads here discussing the (in)ability of an attacker to modify the source-code that Microsoft builds from, or use it to more easily discover vulnerabilities.
What I've not seen anyone discuss is the potential for an attacker to take the source-code of a single Windows core component (a system DLL for example), add in a backdoor, build it and then distribute the binary via a compromise such as the SolarWinds update mechanism.
In other words, insert a modified core Windows DLL into some other popular Windows driver or application package updater published and signed via a 'trusted' channel other than Microsoft itself.