HTML attachment exploits slipping through Exchange Online Protection filters

With Microsoft understandably being extremely hawkish on email filtering the last couple of weeks, we see tons of legit email going to quarantine or end users' junk email folder. Fine, but how come they then let email through with HTML attachments containing code as per the below? Is there ever a legitimate reason to be doing decoding of base64 strings in an email attachment? 


