Does anyone else remember the 27C3 presentation on this? My take away was that Stuxnet was _largely_ enabled by 0day vulnerabilities in Microsoft's products. The especially damning one was the print spooler script running vulnerability.
Anyways, from this perspective, even back then, the analysis was pretty thorough: