From what I have read one of the vulnerabilities seems to be a 0day targeting SMB on Windows. One commentator suggested it's enabled by default on the majority of Windows machines (of that I am sceptical). Presumably most people are behind a router which would stop this in its tracks?
A lot of people (who I would probably take seriously) suggest disconnecting Windows machines from the internet for the time-being. Is it really this bad? Are there millions of Windows (home-)users who are vulnerable (by default) today?