CVE-2026-25166
Windows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability
Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected products
Microsoft · Windows ADK for Windows 10, version 2004Microsoft · Windows ADK for Windows 11, version 22H2Microsoft · Windows ADK for Windows 11, version 23H2Microsoft · Windows ADK for Windows 11, version 24H2Microsoft · Windows ADK for Windows Server 2022Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →