I think it's a point about persistence. It's easy to obfuscate an existing piece of malware to not be found for a day or two, harder to keep it undetected forever. If you instead task schedule code.exe to expose some internal network port, you can keep it for as long as the machine lives.
But that's already assuming you get compromised anyway, and that your compromised workstations have things worth reaching on their internal network/VPN. All things that are true on real corporate networks, but "fixing" this vulnerability is still pretty low impact in the grand scheme of things one could do to to improve the situation. But in my experience, most CISOs aren't that great at setting priorities and threat modeling anyway: One just recently told me they doesn't want XSS vulnerabilities reported, because the scanner would find them anyway - but sends out daily all-caps emails about specific emails being phishing.