I’ve really come to the conclusion that OS users are merely policy barriers and not security barriers (or at least, not strong barriers). This seems to be the position of Microsoft as well, given their stance on UAC and privilege escalation exploits in general.
I think it’s akin to real-life locks. Keeps good guys out, but not a determined attacker.