What if your ISP hijacks your DNS (pretty common) and someone was to poison it and instead downloads a malware ? That would mean thousands of windows pcs download this malware by just connecting to the internet.
This can be a problem if there's some kind of critical vulnerability in the Microsoft HTTP stack, but I don't think this attack vector is all that relevant.
Same with other captive portal detection endpoints, there's very little actual parsing going on with these requests.
Thus: Hijacking WU to download malicious content takes far, far more than just DNS hijacking. You'd also need to subvert the WU signing system. (This is more nation-state level stuff.)