The problem is, a lot of the things which are getting (slowly) patched at the moment are ways to escalate privileges. Once the malware is on the machine, if it can exploit an unpatched bug which escalates privileges, it has access to the whole machine.
Without using such a bug, it can do less damage.
That said, the "code installer" is trying to install codecs into the system, this requires an administrator password, so people aren't adverse to entering the password, because they know they are installing new codecs, to allow them to watch some piece of dodgy video...
