Interesting - this only applies if your user account is already running as an administrator, but the risk here is that administrative functions could be run without user interaction or UAC prompts.
I just tested this on my Windows 10 machine (running the latest 20H2 version of Win10), and I could successfully launch diskpart.exe and other executables without any UAC prompt. Although Windows Defender did block me from launching cmd.exe or regedit.exe.
I would agree with the author that this is a risk that should be fixed.