Private key disclosure seems catastrophic because of their scorched-earth security policy https://lotw.arrl.org/lotw-help/certificatesecurity/ where the server admins plan to invalidate all signed data, even if the same data had been sitting on the central server for years before the compromise happened. Yet, the docs don't recommend a password for the private key except on "shared or public computers." The adversary just looks for -----BEGIN PRIVATE KEY----- in a text file in a keys directory (the filename is the call letters).
In other words, although executing cmd.exe is a wonderful accomplishment, there's also the possibility of 1. wait for the PC and radio to be idle, 2. tune the radio to a clear frequency, 3. open the victim's private key file, 4. transmit the private key with Morse code.