Today, @osxreverser on Twitter announced their analysis of Apple's OS X 10.10.3 fix for CVE-2015-113 privilege escalation (aka "rootpipe") and an adapted unofficial fix for OS X 10.9:
https://twitter.com/osxreverser/status/587639173919727616
Apple apparently added a new private entitlement named "com.apple.private.admin.writeconfig" and made it required for calling the XPC service "writeconfig".
Shortly after 10.10.3 was released, it was discovered that the tool "createmobileaccount" (which can be used to pre-create a mobile account and home path prior to a user with network credentials logging into a machine) was no longer functioning properly.