Manual deployment of out-of-band CU (KB4567512) has not changed a thing, obviously.
I also established that it's not possible to remove single entry from Event log - it's either everything that's get deleted, or nothing.
So assuming that duff entries in Application Event Log are a problem - which I think they are - I am guessing that upgrade to 2004 will kind-of resolve it for me as at that time all system logs will get zeroed. I will update this thread if/when that happens.
Still, I guess it's something that Microsoft should look into.