Those files would be editable by something in the sysadm_t domain which is by default the domain of the root user after a successful authentication
This backdoor does not bypass remote authentication so it should be able to transition to the new domain that has access to these files