CVE-2026-25166

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
10/03/2026
Last modified:
11/03/2026

Description

Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

References to Advisories, Solutions, and Tools