It is truly disappointing to see Microsoft go its own way with an “exploitability index” that is so coarse in its own scale and so similar to other scales (e.g. CVSS and even MS’ own ratings) that it simply adds noise to the overall vulnerability rating arena.
Personally I think Microsoft should by default just list a criticality label for the whole vulnerability to avoid confusion and noise. That said, Microsoft already has a full DREAD rating for the vulnerability internally, and they could display that in a div that is hidden by default but displayed when an advanced user clicks on a “show details” link or something similar. That way advanced users could make patch decisions based off of the specific details if they chose, but less advanced users wouldn’t be confused.