The host is installed with Sun JDK or JRE 6 Update 10 or earlier, 5.0 Update 16 or earlier or 1.4.2_18 or earlier and is prone to a privilege escalation vulnerability. A flaw is present in the application, which fails to properly enforce context of ZoneInfo objects during deserialization. Successful exploitation could allow attackers to run untrusted applets and applications.