Actually the way patches are digitally signed, and it has to match up with a Microsoft cert authority while one never says anything is impossible, one can't inject something into the update without first compromising the entire OS's cert checking process. And in this case, an attacker would be REALLY stupid to go through all that trouble to compromise the cert checking process and then blow it on the actual attack sequence.
This is true. Unfortunately, that system has indeed already been compromised at least once. http://www.wired.com/2012/06/flame-microsoft-certificate/
People can reasonably be concerned and mistrust their computers until they get a clear answer.