Sitting at the computer, to me, means not an exploit.
IMHO, anything where the machine needs to ALREADY be compromised is not at fault for compromising a machine.
If you have to have a user's password. . . and then an Administrator's Name and password to compromise the machine, it isn't an exploit. . . it's a novelty, a potential to do something with the computer.