Deserialization Vulnerability in Windows System Image Manager by Microsoft
CVE-2026-25166
7.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-25166?
A deserialization vulnerability in the Windows System Image Manager enables an authorized attacker to execute arbitrary code locally. This may lead to unauthorized actions on the affected system, emphasizing the need for updates and patches to maintain system integrity.
Affected Version(s)
Windows ADK for Windows 10, version 2004 -
Windows ADK for Windows 11, version 22H2 -
Windows ADK for Windows 11, version 23H2 -