local administrator privileges
... are used by distro update mechanisms and very few people turn those off, even if they don't use elevated privileges for anything else.
Admittedly, it's unlikely that a distro's repository will end up with a compromised microcode package, but it's not impossible (Remember the 7zip debacle?). And if it happens, you can be sure that whoever designs the payload will use the temporary access to install something ugly that has more permanent access.
But as you say, AMD have issued a fix. And that'd be why.
Pretty sure there are some modern ones floating around after someone else took up the strip, but yes, many of them are from way back.