Fair point, but all that does is highlight further the insecure model running applications on the desktop, and of storing passwords. Other applications that run in userspace have access to everything! What should happen is that Microsoft Credential Cache should only grant access to a small part to any program wishing to store the password, and deny access to _other_ credentials from another program. If they wish to access something more, then it should prompt.
As far as the gullible admin, well.. that's their own fault.