For example, antivirus products do this all the time, as do many video drivers and other system utilities.
Also, Explorer has various plugin interfaces where it'll load third party code and run it in-process since the very first version.
The OS isn't to blame when people give root access left and right.
Actually this is why macOS got SIP.
The shift towards protections from malware happened mostly as a consequence of Windows XP. There are now better controls, like assigning low-trust processes like a browser's renderer a low integrity level to prevent them from doing that. But it's also late enough that it's hard to rock the boat too much without breaking existing applications. Microsoft tried to make a clean break and offer more sandboxed applications with a user-friendly package manager (called the Microsoft Store) but this wasn't well received by app developers: most didn't use it at all, and those that did often opted out of the sandboxing.
From microsoft's documentation [1] > Administrator-to-kernel is not a security boundary.
I recommend the talk https://www.youtube.com/watch?v=Y09nAxZFKzc
[1] https://www.microsoft.com/en-us/msrc/windows-security-servic...