While I'm not a fan of the almost forced OOBE setup, I really don't understand the complaining regarding security. It's again another case of if you can run code on my computer you already own it. As Raymond Chen put: "you’re already on the other side of the airtight hatchway. And you’re bragging that you can do something annoying like a denial service, apparently unaware that being on the other side of the airtight hatchway gives you the ability to do far more interesting (and threatening) things".
This kind of "vulnerability" has been a constant topic of his blog in the past:
https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31... https://devblogs.microsoft.com/oldnewthing/20181219-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20121207-00/?p=58... https://devblogs.microsoft.com/oldnewthing/20180227-00/?p=98... https://devblogs.microsoft.com/oldnewthing/20240404-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20200420-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20220907-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20240102-00/?p=10... https://devblogs.microsoft.com/oldnewthing/20070807-00/?p=25... https://devblogs.microsoft.com/oldnewthing/20230206-00/?p=10...