I think it's also probably somewhat common for run of the mill employees to use privilege escalation exploits to get admin access to do regular tasks. At least it was common in places I've worked where your local PC was so locked down that you couldn't do your job, and the official process to work around that wasn't reasonable. Enough people doing that opens up other unintended holes.