“Malware targets the user as the vulnerability”
Indeed it does - for secure systems. For insecure systems like Windows and IE, malware targets the system insecurities directly, which is why Microsoft issues a steady stream of SECURITY UPDATES. These security updates are not fixing broken users, they’re fixing broken software.
Please provide the source documentation.