
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25166 is a deserialization of untrusted data vulnerability in Windows System Image Manager (SIM) that allows an authorized, low-privileged local attacker to execute arbitrary code. Disclosed on March 10, 2026, as part of Microsoft's Patch Tuesday release, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, and 2022 (including the 23H2 edition). It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is rooted in improper handling of deserialization processes within Windows System Image Manager, classified as CWE-502 (Deserialization of Untrusted Data) and mapped to CAPEC-586 (Object Injection). An attacker with low-level local privileges can supply crafted, malicious serialized data to the application, which is processed without adequate validation, triggering arbitrary code execution. Notably, no user interaction is required for exploitation, and attack complexity is rated low, meaning a straightforward exploitation path exists once local access is obtained (Microsoft MSRC, Feedly).
Successful exploitation grants the attacker full control over the affected system, with high impact to confidentiality, integrity, and availability. A low-privileged local user could escalate their access to execute arbitrary code in the context of the vulnerable process, potentially enabling persistence, credential theft, or lateral movement within the environment. The broad scope of affected platforms — spanning multiple Windows 10, Windows 11, and Windows Server versions — significantly widens the potential attack surface in enterprise environments (Microsoft MSRC, Feedly).
Microsoft released patches on March 10, 2026 addressing this vulnerability across all affected platforms. Administrators should apply the following minimum patched build versions: Windows 10 21H2/22H2 (10.0.19044.7058 / 10.0.19045.7058), Windows 10 1607 (10.0.14393.8957), Windows 10 1809 (10.0.17763.8511), Windows 11 23H2 (10.0.22631.6783), Windows 11 24H2 (10.0.26100.7979), Windows 11 25H2 (10.0.26200.7979), Windows 11 26H1 (10.0.28000.1719), Windows Server 2016/2019 (10.0.14393.8957 / 10.0.17763.8511), Windows Server 2022 (10.0.20348.4830), and Windows Server 2022 23H2 (10.0.25398.2207). Where immediate patching is not feasible, restrict local access to Windows System Image Manager and enforce the principle of least privilege to reduce exposure (Microsoft MSRC).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by several security outlets. Rapid7, Sophos, Zero Day Initiative, and SANS ISC all included CVE-2026-25166 in their Patch Tuesday analyses, noting it as one of 78 vulnerabilities addressed that month (Rapid7 Blog, Sophos Blog, ZDI Blog, SANS ISC). Community reaction was measured, with no significant alarm given the local-only attack vector and absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."