Deserialization Vulnerability in Windows System Image Manager by Microsoft
CVE-2026-25166

7.8HIGH

What is CVE-2026-25166?

A deserialization vulnerability in the Windows System Image Manager enables an authorized attacker to execute arbitrary code locally. This may lead to unauthorized actions on the affected system, emphasizing the need for updates and patches to maintain system integrity.

Affected Version(s)

Windows ADK for Windows 10, version 2004 -

Windows ADK for Windows 11, version 22H2 -

Windows ADK for Windows 11, version 23H2 -

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.