This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell commands.
No PoCs from references.
- https://github.com/0xT11/CVE-POC
- https://github.com/ChiChou/sploits
- https://github.com/ThePirateWhoSmellsOfSunflowers/TheHackerLinks
- https://github.com/alphaSeclab/sec-daily-2019
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/genknife/cve-2019-8513
- https://github.com/hectorgie/PoC-in-GitHub