NSA would find lots of exploits. Many black hats would, too. The key difference I see from high-assurance security is that there will be a diverse array of protections developed that might stop anywhere from some to all attacks. There's a pile of them out there in CompSci, private sector, and so on for Linux, FreeBSD, and Android. Tiny portion of that R&D goes to Windows kernel or privileged userland. Microsoft Research even builds great tools Microsoft themselves won't even use in the general case even though they applied some of them.
To put this into perspective, there's CPU modifications that can make a Linux or FreeBSD system mostly safe and secure against known classes of attack instantly just at the compiler and CPU level with a certain performance hit. Anyone wanting improved security could then use Linux with those CPU's probably buying some extra chips, too, to cover performance loss. You don't have that option with Windows.
To put this into perspective, there's CPU modifications that can make a Linux or FreeBSD system mostly safe and secure against known classes of attack instantly just at the compiler and CPU level with a certain performance hit. Anyone wanting improved security could then use Linux with those CPU's probably buying some extra chips, too, to cover performance loss. You don't have that option with Windows.
http://www.cl.cam.ac.uk/research/security/ctsrd/cheri.html
http://sva.cs.illinois.edu/pubs/KCoFI-Oakland-2014.pdf
https://www.cs.rutgers.edu/~santosh.nagarakatte/softbound/