It’s been 4 days since the last remote-exploitable, no-auth-needed RCE hole in Windows. If you were running this version of Windows, you would not get the patch automatically delivered to your device.
Certainly. The question is what provisions the software has made to mitigate those potential vulnerabilities by notifying users that a patch is available and allowing them to automatically apply that patch.
Deliberately removing these mitigations from a piece of software which is highly exposed to exploits, like a web browser or an operating system, is nothing short of irresponsible.
Most no-auth exploits take advantage of the user already being an administrator, and then bypassing UAC for example. The configuration mentioned above would likely mitigate this issue, although I'm not educated enough on this subject to say for sure