"Acquiring an unlocked machine requires and act of God.
Or maybe a quick perusal of a couple of articles from 2600.
It is really very difficult to stop a privilege escalation attack if the user has an account on a box, particularly a Windows box.
No, actually it's very easy ... they just fire the first two or three that exercise their "freedom" and the problem goes away.