I am impacted by this and am furious about it. Mostly because I'm reading about it here and not from, you know, Microsoft, of whom I am a customer.
If Apple can release updates for ancient iOS versions to update certificates years after the fact, then these fucking assholes can do the same. The auto-update functionality is there. They are choosing not to use it.