Hackers exploit gaping Windows loophole to give their malware kernel access
arstechnica.com
arstechnica.com
Maybe, but if a system running today has no drivers installed signed by old certs, transparently blocking them, as well as defaulting to block, with an IT admin ability to unblock, for new installs seems quite easy.