You are hugely overestimating the level of security of software like this. There's a constant stream of vulnerability discoveries, disclosures and fixes. Those vulnerabilities don't pop into existence the week someone publicly discloses them and informs the vendor, they've been waiting there for anyone to find them for years.
If MS wanted to replace a product like this with one that has a low probability of containing any remotely exploitable vulnerabilities, they'd have to go back to the drawing board, do a full rewrite witha completely different sw development process, take a lot of time or make some major functionality compromises (or probably both).