Steve Gibson, creator of the firewall Leak Test believes that the WMF vulnerability was deliberately programmed into Windows. He hypothesizes that Microsoft could have put it in for a situation where they had to bypass admin settings, firewalls, AV, to execute code on the machines of visitors to their website via an image file.
If you want the counter explanation see the Microsoft Security blog entry. They explain that the vulnerability was introduced in 1990. Lots of old code hanging around Windows. Mr. Gibson is being spooked by ghosts of the past.