It's not that much a vulnerability, than it renders UAC completly useless. There is no use for it anymore since any program with standard rights can change it's setting to get admin rights.
It's just going back to XP level of security !
It's the same as "Safari carpet bombing issue" : http://www.theregister.co.uk/2008/05/31/microsoft_warns_against_apple_safari/
It will transform any "little security breach" into a full admin security breach !