And you might want to disable the root account again with `dsenableroot -d` as well, so that the root account stays disabled after the vulnerability is patched.
Unlike doing this through the GUI, this seems to retain the root password and prevent this vuln from re-occuring.