CVE-2025-35975 Details
Description
MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM file for exploitation.
A vulnerability allowing an out-of-bounds write has been identified in MicroDicom DICOM Viewer, versions 2025.1 (Build 3321) and prior. This vulnerability may enable an attacker to execute arbitrary code, but exploitation requires the user to open a malicious DCM file.
Users are advised to update MicroDicom DICOM Viewer to version 2025.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 1, 2025CISA-ADP
Assessed May 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-121-01 | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MicroDicom DICOM Viewer | <= 2025.1 (Build 3321) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2025 | New CVE Received | [email protected] |
Volerion