I don't know, it really doesn't sound like a real CVE - maybe add some setting I guess for those worried? Others bring up good points, if your attacker can write to C:\ you probably have other issues.
On top of that, it breaks completely valid functionality - someones 'bug' is someone elses feature.
On top of that, it breaks completely valid functionality - someones 'bug' is someone elses feature.