Sounds to me like a loop hole tinyMCE created though its self-advertisement. I have no Windows desktop around to test, but you said, you reproduced it easily. Doesn't the switch in the screen Markus mentioned react?
If not, a topic for the security forum?
What is the exact version of your Moodle, something like Moodle X.Y+ (Build: YYYYMMDD)?