Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability
(www.theregister.com)
You might be right. I think that the Linux kernel doesn't have an ABI though, so I believe the driver has to be built for the current version of the kernel. I think the idea is also that the driver is signed by the distro, not Microsoft, so the risk of random drivers getting signed accidentally is probably much lower.