Earlier quoted context omitted.
The article assumes you have enough access to boot the computer from an alternative medium. They can't just "fix" that short of forcing full disk encryption.
I was referring to the login GUI running with full privileges, meaning any time someone finds an arbitrary code execution vulnerability in the GUI they can get full admin access. I wasn't referring to using a boot disk to reset a password. As far as I'm concerned that's a feature not a vulnerability, and it's a feature Windows makes unnecessarily hard to access.
You are, however, technically correct, but finding arbitrary code execution vulnerabilities in the "GUI" these days is not a trivial task. And if you've done that, you can do anything you want to the system.
As Raymond Chen (Windows API developer) would say "that would involve being on the other side of this airtight hatchway".