Windows MSI files provide an opening for attackers even though the bug was mostly patched in July.
Source: Threadpost