A user classified as an editor, can edit himself as system administrator. This is accessible via people page. The user can only edit himself, but he has an option to make himself system admin. I'm suspecting this doesn't alter the users permissions, but this is an interface problem that needs to be looked at.
the unauthorized check box