You’d think that, but depending on where you are with your updates that’s not always true.UAC was a good idea. But it seems to have been botched, universally panned, and disabled everywhere but enterprise. Seems that this would intercept all of the "not a person at the keyboard" attacks.
Also plenty of Linux based exploits too that can seamlessly elevate a command too based on updates.
But yes UAC was good, legacy software though just doesn’t use the correct API’s and doesn’t trigger it like you’d expect.