SMBv1 has effectively been removed for modern clients and thus is not 'unpatchable'.
Encryption is on-by-default with SMBv3, I believe.
So some of these mitigations are already in place. I'm sure the UEFI issues will always persist, that's not a Microsoft issue per se, and I assume the kernel memory management potential vulnerabilities are still present, though the author doesn't offer any concrete proof in the report that these are exploitable as of today.
Good luck, I like the report format! Hopefully we hear from you again on the truly nasty vulnerabilities.
vinhatson•7h ago