My impression was that Vista faired better then XP with respect to the MS08-067 bug mostly because of the DEP/ASLR combination. I'm not sure UAC really figures into it.
I went into this in more detail in this blog: http://blogs.pcmag.com/securitywatch/2008/11/why_vista_looks_good_after_the.php