Actually the way patches are digitally signed, and it has to match up with a Microsoft cert authority while one never says anything is impossible, one can't inject something into the update without first compromising the entire OS's cert checking process. And in this case, an attacker would be REALLY stupid to go through all that trouble to compromise the cert checking process and then blow it on the actual attack sequence.
"Simply injecting content into the update description" isn't simple at all. It feels more like a Microsoft patch oopsie than anything nefarious. Bottom line the update mechanism isn't easily compromised, typically requires physical access or some sort of physical injection of the cert attack (as I recall Flame malware injected itself with compromised USB devices). It's one of the reasons that Microsoft can do peer to peer updating in Windows 10 and can assure that the bits coming to us from anywhere are still official Microsoft bits.
My point was if something is listed in the update history as failed you can't "hide" that one item, the update database doesn't work that way.
My gut tells me someone oopsie'd on Microsoft's side and I'm doing my best to confirm.