In his demo video, he needs to run a specially crafted program to actually achieve privilege escalation. That's why you need both physical access and a local user account.
Social engineering only gets you both if you can autorun the executable upon insertion of the usb stick.
Social engineering only gets you both if you can autorun the executable upon insertion of the usb stick.