Remote code execution - aka they can run arbitrary code on the compromised machine via the bug.
Basically the worst possible thing.