Why did DCOM fail? Yes, sure, the protocol documentation is extremely obscure and the tooling kind of sucks, but conceptually? I assume that there’s a reason aside from Microsoft choosing to jump on the web services bandwagon, but I can’t actually find anyone come out and say it. The closest I’ve seen is complaints about scalability, but they don’t agree what’s at fault, either—some point to pinging, some to heavyweight COM+ activation... I don’t get it. Given the relative success of seemingly-isomorphic Java tech, there has to be something.
This would be a good contrast, rather than a vulnerability being hidden for years in rarely-updated software, you get a vulnerability that sneaks in without you knowing you've updated anything.