How prevalent are bootkit (MBR) malicious exploits though? Surely the right place for this is for windows to prevent boot modification without authentication though UAC or something similar?
Secure boot is a form of defense in depth that is really only needed if the kernel is compromised. So yes, the attacks that it prevents are hypothetical and may never exist. And yes, it may be too high a price to pay for the unknown level of protection that it provides.
A compromised kernel does not seem that unlikely. I am not fammilar with Windows, but I assume it supports hotloading code into kernel space (like modules in linux), given this, it would be trivial to get from root in userspace to arbitrary code execution in kernel space.
Between driver signing and kernel patch protection, it's harder than you think. But clearly Microsoft is preparing for that sort of compromise.
If some signed driver is found to have an exploit, is there a mechanism to revoke the signature?
It already exists.
http://www.stoned-vienna.com/
I also read that it was trivial to make a "boot kit" for Windows 8 without secure boot. I actually think it a very big deal and hope many Linux distro's develop something similar.