> Any details of what level of local access is needed for a local exploit? In particular, is this exploitable from inside a VM? That would be really bad news for AWS, Google Cloud, or Azure. 
Published details remain vague.

One could also ask what level of *network* access is required.  If simply the ability to send a packet to the machine is enough, perhaps you could break into one VM's host from a different VM - since VM's you own can send each other packets.
