A user who has only READ permissions into a VCR can copy a GPO.
If a user has the create permission through a role anywhere below a container where block inheritance is set, the copy and paste options on the right click menu will be enabled and work even if inheritance has been blocked on that container and the user has been given a role without the create right (the create right is what is used to determine copy / paste functionality). In this situation the user can copy and paste a GPO even when they only should have read access on the container and containing objects.
We have isolated this to a specific interaction between how copy and paste work within MMC and how the create permission was implemented. It does not affect any other permissions. Note that the "Cut" and "Delete" options will not work as the "Delete" permission is blocked correctly when inheritance is blocked, it is only the copy and paste functionality which require "Read" and "Create" that are affected and allow the paste due to the create permission not being blocked.
We have created a defect to have this evaluated for a fix in a future version of GPOADmin.
The defect ID for this is 568761.
This will be considered for the next version / next patch release whichever comes first.