CyberICT

CVE-2026-25166

Microsoft · Published March 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability. Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

Affected Products

  • Windows ADK for Windows 11, version 24H2
  • Windows ADK for Windows 11, version 23H2
  • Windows ADK for Windows 11, version 22H2
  • Windows ADK for Windows Server 2022

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C