It rather involved being on the other side of this airtight hatchway: Elevation to administrator
Surprisingly, it is not a security vulnerability that administrators can add other users to the Administrators group. But that doesn't stop people from claiming that it is. For example, it's not uncommon for a vulnerability report to come in with the following steps: Wow, this looks bad. An unprivileged user can elevate to administrator and... ...