Bobbie Harder's explanation makes no sense - other posters above have clearly pointed out that what was approval only for an update to a PC with WDS on it has morphed into approval for installation of the whole product. This is completely unacceptable. I spent some time yesterday removing WDS from all the PCs in our small business, which I could have spent a lot more productively doing other tasks. The "Automatically approve new revisions of updates that are already approved" setting is now turned off in WSUS, and I would advise everyone to do the same.
MS need to apologise for what has happened, rather than try to justify it, and should be issuing an update ASAP that will allow WSUS Admins to remove the WDS malware. I would not like to be the sysadmin who reportedly wound up with 3000 PCs having this installed...