It doesn't, that much.
The problem really is for the defenders that are half-assing their defensive strategy or putting in "good enough" controls. It basically eliminates any leeway or grace period defenders might have between initial compromise and lateral.
I've been on exactly one engagement that I think would be in good shape against this kind of threat, and that client literally implemented every suggestion in our report from the previous year to the letter.
Basically, this is just going to make doing the basics properly (notably, asset management, patch management, and network segmentation) a harder requirement for doing business than it previously was.