CVE-2026-25166

7.8

Microsoft · Windows System Image Manager

A deserialization vulnerability in Windows System Image Manager allows an authenticated local attacker to execute arbitrary code.

Executive summary

A deserialization vulnerability in the Windows System Image Manager within the Windows Assessment and Deployment Kit (ADK) poses a significant risk of local code execution for authenticated users.

Vulnerability

The software suffers from CWE-502: Deserialization of Untrusted Data, which allows an attacker with local, authenticated access to execute code on the host system. The CVSS vector (AV:L/PR:L/UI:N) confirms that the attacker must be logged into the system with low privileges to trigger this flaw.

Business impact

Successful exploitation of this vulnerability permits a local user to escalate their privileges or execute arbitrary commands with the permissions of the application, potentially leading to a full system compromise. With a CVSS score of 7.8, this vulnerability is classified as High severity, necessitating prompt attention to prevent unauthorized lateral movement or data exfiltration from affected workstations or servers.

Remediation

Immediate Action: Review the official Microsoft Security Update Guide for CVE-2026-25166 and apply the recommended security patches or configuration changes provided by the vendor.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unauthorized attempts to access or modify Windows System Image Manager configuration files.

Compensating Controls: Restrict access to the Windows Assessment and Deployment Kit (ADK) to only those users who require it for administrative tasks, thereby reducing the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the Windows Assessment and Deployment Kit should prioritize the identification of all instances of the affected versions across their environment. Given the potential for local code execution, applying vendor-supplied updates as soon as they become available is the only effective way to neutralize the risk posed by this deserialization flaw.

More Microsoft CVEs

Sources