CVE-2026-25166
HIGHWindows System Image Manager - Deserialization
Title source: llmDescription
Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
Scores
CVSS v3
7.8
EPSS
0.0060
EPSS Percentile
69.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
draft
Timeline
Published
Mar 10, 2026
Tracked Since
Mar 11, 2026