It doesn't surprise me as Windows 10 is basically tracker software without modification so installing a non publicized backdoor with a Coexnant verification signature could imply it's a CIA/NSA approved codex. Although the part that says there is no evidence that this keylogger has been intentionally implemented, could also be plausible deniability as the note mentioned and code is sloppy but their is always the point of do people really check these things and if they do it takes a while so until its pointed out we can just run with it etc.
"Obviously, it is a negligence of the developers - which makes the software no less harmful. If the developer would just disable all logging, using debug-logs only in the development environment, there wouldn't be problems with the confidentiality of the data of any user."
Still since HP and Conexant were moot on the topic when modezero mentioned it so the former seems plausible.