Following on from APG's post, I thought I would change my own password, in part to see why the system would not accept her new password. I found myself unable to do so...
Until, that is, I thought to enter the new password as my "current" password in the final box, and then it *was* updated. I have checked, and the new password is now accepted, so I've successfully changed my password now.
Needless to say, this is seriously flawed as a security measure. If an account is ever active and accessible (eg on a computer left briefly unattended), anybody could change the password without ever needing to know the original.