This is a buffer overflow vulnerability allowing to execute code remotely, without authentication (it's ICMP 😉 ) on a target and to take control of it.
It is therefore particularly important to update, or at least block ICMPv6 on the local firewall or network firewalls. In cases I have tested, some firewalls with poor ICMPv6 support let these packets through, rendering them inoperable.
Microsoft's internal RedTeam has a working private PoC so I assume other teams also have working exploit code as the McAfee article is quite detailed and with the patch out, it has already been analyzed to understand its behavior.
Related articles: