But it supercharges what can be done once you get root, no?

By a LOT. It would expose the data Windows keeps isolated using virtualization based security.

Does this mean the exploit can be used in a VM to get access to the host machine?

Yep.