CVE-2026-25166
Microsoft · Published March 10, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability. Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
Affected Products
- Windows ADK for Windows 11, version 24H2
- Windows ADK for Windows 11, version 23H2
- Windows ADK for Windows 11, version 22H2
- Windows ADK for Windows Server 2022
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C