The fact that random companies like Crowdstrike have kernel drivers in millions of computers they they ship remotely is a security risk in and of itself. We're lucky crowdstrike just shipped a bug that crashes computers, other companies could have shipped a lot worse.
Sure, there are vulnerabilities. But UEFI offers features such as secure boot, which BIOS doesn't. Also, its nice being able to boot from drives larger then 2tb.