The attacker needs to have access to the targeted system and they must be able to execute arbitrary code.
So if your systems are already locked down, you should be OK.
Tell that to PCI-DSS auditors.