No, there is no local privilege escalation. So at best this can hit the four machines in the world that run bash CGI scripts as root.
Also, their apt-get command is incorrect. apt-get update updates the local repo cache, apt-get -yy install bash will upgrade the bash package. So now they're down to two of the four machines, the ones that run RHEL.
All their exercise has done is to land their crawler IPs on some lists of IPs attempting to exploit this vulnerability. I don't think that will help them any with their business.