Not signed?
I used to work on assistive technology before pretty much any security was added to Windows and you could hook in to all the UI calls an application made to build a comprehensive screen model. I left that field almost 20 years ago, but thought the whole point of inter-application security busting assistive APIs is that they would be restricted to signed code which had been thoroughly vetted. It doesn't really come as any surprise that Microsoft have failed on this too.