Security is a more complex terrain than that Microsoft vs. Free Software space people keep insisting to drag the discussion into. Dragging it into this place is a straw man.
A straw man compounded to your ad hominem is not up to the usual standards here.
It is possible for you to hire people to secure an open platform from the ground up. It is up to Microsoft to secure Windows from top to wherever they think the cost exceeds the benefit for them. That's a key difference - it doesn't matter how much effort you spend securing Windows, if you are not Microsoft, you can never be sure of the results until you find them out the hard way.
Yes. I do like Free Software and I use it extensively. I also use Sun, Oracle, IBM, SAP, PeopleSoft and, from time to time, even recommend MS SQL Server when it makes sense. It would, however, be insane to simply disregard Microsoft's software appalling security record or to oversimplify it as a Free vs Evil dichotomy. It's not.
It's just that Microsoft seems to spend more money promoting their wares than properly checking and securing them. Security seems to be grafted on instead of built into.
And, for the other argument, of security issues arising only from adversarial conditions and not bugs, that's simply incorrect. Software that's correct should not have holes like unchecked buffers that allow code injections. And it's not only Microsoft who's guilty here - just about every product I use seems to have fallen for this one in a given point in its history. Still, the fact others face it does not make Microsoft's products more secure. Like I said, it's a more complex issue than this false dichotomy.
As for more sophisticated attacks that rely on memory access patterns, memory protection mishandling, improper erasure and so on, well... If the processor is not, itself, correct, you can't really expect the software to cover all the holes - only the possible ones.