Unfortunately if you can read a configuration file in a user's home directory, you can also get local admin rights very easily via various simple exploits.
This is why RCE type exploits are super dangerous.
There probably won't ever be a solution for this unless we get a completely rewritten Windows / Linux with pure security in mind.
I wonder if any VC would invest in a startup to build a secure OS.