Earlier quoted context omitted.
Using this exploit, connected non root users can gain root access. Multiple user machines are more or less a thing of the past. These days most common use case of ssh is logging in to a remote server you already own with root privileges. So most of the users are unaffected by this exploit.
> These days most common use case of ssh is logging in to a remote server you already own with root privileges I only see this in relatively small and "young" teams. In any bigger organization I've worked in, a new user is created for each person who uses the machine.
The script is pretty straightforward, see AuthorizedKeysCommand and https://github.com/{$user}.keys