According to the advisory at http://seclists.org/fulldisclosure/2010/Apr/119:
"All versions since Java SE 6 update 10 for Microsoft Windows are believed to be affected by this vulnerability. Disabling the java plugin is not sufficient to prevent exploitation, as the toolkit is installed independently."
Harmless demonstration at http://lock.cmpxchg8b.com/bb5eafbc6c6e67e11c4afc88b4e1dd22/t...