The NSA rarely goes public with respect to OS vulnerabilities, tending to save them for possible future exploitation.
This vulnerability which they discovered was deemed sufficiently serious to require public notification of the need to patch immediately:
https://www.infopackets.com/news/10692/critical-windows-10-bug-needs-immediate-fix
The patch can be done through Windows Update, or manually.
The linked infopackets article by John Lister is pretty interesting regarding the NSA's usage of OS weaknesses, apart from the current one.