The agents discovered the vulnerability, but they are not necessary for a virtualized workload to exploit them.
This is more a story of how VMs won't reliably contain a malicious workload, and the story was exposed via agents.