Note that this only affects Mac OS 10.13 High Sierra, not any older OS versions.
Really is astonishing that this could have made it through to shipping software. Also astonishing that this has taken so long to be highlighted. The latest point release, 10.13.1, came out on October 31, 2017. It took 28 days for this to be found?!? I haven't seen anything that clearly says if this bug was present in earlier versions--10.13.0 or any of the beta versions.
BTW, Apple is expected to release a fix shortly:
http://appleinsider.com/articles/17/11/28/apple-says-fix-incoming-for-macos-high-sierra-root-access-bug
Craig