The weak point is the identity-reset path, not the endpoint. If an attacker can convince a help desk to reset a password, change MFA, or start a remote support session, they get the same privileges the support team uses to open accounts and grant access.
Recent cases across M&S, Co-op, Harrods, Carnival, and the FBI’s warning on Silent Ransom Group show the pattern keeps working. These attacks bypass software defenses and turn third-party service desks into a relay for account takeover, which is why patch-first thinking misses the blast radius.