It's an interesting conundrum. One could argue this is a precedent. Then it becomes a question of "for what levels of severity do they patch vulnerability for?".
Exactly! IMHO Microsoft shouldn't have released the patch to people that aren't paying for extended support. It is just going to encourage cheap CIOs to continue to ignore their dying infrastructure. They just doomed themselves to another 10+ years of Windows XP support.