With the public advisory by Determina about a double-free bug in a CSRSS message function, the immediate question was: does it really affect Vista? The short answer is "yes, but not reliably." Arbitrary code execution is possible, but requires a great deal of luck, though a denial-of-service is definitely possible.
Why the fuss? Simply put, successful exploitation of the bug allows even the most restricted user-mode application to elevate its privileges to the System level. From there, the kernel is accessible even on Vista. Even without entering the kernel, System-level privileges allow almost complete control of the system, so the possibilities are limited only by the imagination.
Of course, that the bug isn't reliable on Vista doesn't mean that everyone can relax. The bug does affect earlier versions of Windows, where arbitrary code execution is far easier to achieve. Is it likely to be exploited? Oh yes. Not such a happy New Year.