cbcvebase.
CVE-2026-25166
published 2026-03-10

CVE-2026-25166: Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftwindows_10_1607< 10.0.14393.895710.0.14393.8957
microsoftwindows_10_1809< 10.0.17763.851110.0.17763.8511
microsoftwindows_10_21h2< 10.0.19044.705810.0.19044.7058
microsoftwindows_10_22h2< 10.0.19045.705810.0.19045.7058
microsoftwindows_11_23h2< 10.0.22631.678310.0.22631.6783
microsoftwindows_11_24h2< 10.0.26100.797910.0.26100.7979
microsoftwindows_11_25h2< 10.0.26200.797910.0.26200.7979
microsoftwindows_11_26h1< 10.0.28000.171910.0.28000.1719
microsoftwindows_adk_for_windows_server_2022
microsoftwindows_server_2016< 10.0.14393.895710.0.14393.8957
microsoftwindows_server_2019< 10.0.17763.851110.0.17763.8511
microsoftwindows_server_2022< 10.0.20348.483010.0.20348.4830
microsoftwindows_server_2022_23h2< 10.0.25398.220710.0.25398.2207
msrcwindows_adk_for_windows_10_version_2004
msrcwindows_adk_for_windows_11_version_22h2
msrcwindows_adk_for_windows_11_version_23h2
msrcwindows_adk_for_windows_11_version_24h2
msrcwindows_adk_for_windows_server_2022