i agree with that .. this isn't remote at all.
This would be a target for a sql injection exploit and so is remotely exploitable
As a standalone issue I agree with the GP comment - this bug is not a RCE issue, it's privilege escalation.
Some setups serve mysql over tcp/ip, sometimes even on the internet. Maybe you wouldn't trust mysql's ssl usage or username/password auth mechanisms, but they are there, and some people use those features. So this should certainly be considered a remote vulnerability, as long as the exploit can be launched from the client side of a mysql connection.