I was going to say "surely this is against a specific implementation" and would offer that linking to the Microsoft page would convey both pieces of information: the original link and to whom it applies: https://msrc.microsoft.com/update-guide/vulnerability/CVE-20...
tl;dr
> An attacker could send a low-level protocol error containing a fragmented IP packet inside another ICMP packet in its header to the target machine. To trigger the vulnerable code path, an application on the target must be bound to a raw socket.