I'll have to look back for the couple of articles I saw in the last week saying that because the hypervisor (VMware, Xen, VirtualBox, etc.) is running on the CPU directly, it is vulnerable. And once that's the case, the VMs are vulnerable because, let's face it, they're all running on the same CPU, albeit through a virtualization layer.
I think the crux of it is that the virtualization layer does not block the bug.
But I need to find the references. I'm not clear yet on every detail.