You can literally kerberoast Azure AD by default, and that's a known to be used in the wild attack vector since 2014. In a cloud service. Today.
Spammers literally rent Azure VMs because they know that the IP range of azure is not processed by Outlooks/Exchanges email filters.
So often researchers did the right thing and disclosed everything correctly just to get Microsoft to say "oh yeah here is another RCE, but we don't give a damn. Oh, and there is no patch either."
It's just so ridiculous.
There's even unfixed RCEs of VBA from the Office 2013 days which still work, because the mentality of never touch a running software creeped into how Office is built (which is: have a literal copy of all outdated Office versions for the sake of compatibility).
And then people wonder why "Hackers" always say that Microsoft is insecure and why ISO27001 is now a google dork to find easy to hack victims.