Fixing Windows installs that don't receive updates to their trusted roots

Correct.
The reason DST Root CA X3 still exists in the default chain is only for older Android devices that don't care about the expiration date of the root certificate, however, for other operating systems, it must have the ISRG Root X1 certificate locally.
You can try downloading the "ISRG Root X1" certificate in Chain of Trust - Let's Encrypt and put it in the "Third Party Root Certification Authorities" directory of Windows 7 to verify that this resolves the issue.

1 Like