I think these insufficient rights re-evaluation issues are known for years. But nobody opened a CVE until....yesterday.