Matt Miller, a security engineer at the Microsoft Security Response Center, said that zero-day attacks are only rarely effective against the latest versions of Windows.

In new statistics released a few hours ago, Miller stated that of all the zero-day attacks carried out from 2015 to the present, only 40% of them managed to exploit the most recent versions of Windows.
In essence, the vast majority of zero-day attacks only manage to affect older operating systems. Thus, users who keep their systems updated manage to protect themselves from attacks.
Miller also said that the protection of updated systems is due to the mitigations Microsoft recently. He also analyzed the attempts of these attacks between 2015-2019, since Microsoft released its most powerful card to date, Windows 10.

In one of his most recent talks, at the security in Israel last February, Miller shared statistics that showed that Windows vulnerabilities were more likely to be exploited as zero-days, before the company had time to release a patch , or months later, after companies failed to patch them.
Of course, we cannot ignore that, according to recent statistics, hackers will move to older versions of Windows in order to identify flaws and attack them.
Miller's colleagues also announced plans to replace the two main Windows languages, C and C++, with the Rust programming language. This is because, according to studies they are conducting, Rust is a programming language that focuses on security and thus reduces memory-related bugs.
