PatchSiren cyber security CVE debrief
CVE-2025-35975 MicroDicom CVE debrief
MicroDicom DICOM Viewer is affected by an out-of-bounds write that may allow arbitrary code execution when a user opens a malicious DCM file. CISA published the advisory as ICSMA-25-121-01 on 2025-05-01 and later revised it on 2025-05-06 for typos. MicroDicom’s remediation is to update DICOM Viewer to version 2025.2 or later.
- Vendor
- MicroDicom
- Product
- DICOM Viewer
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-05-01
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-05-01
- Advisory updated
- 2025-05-06
Who should care
Organizations and users running MicroDicom DICOM Viewer, especially healthcare, imaging, and workstation teams that handle DCM files from external or untrusted sources.
Technical summary
The supplied advisory describes an out-of-bounds write in MicroDicom DICOM Viewer with the user interaction condition that a malicious DCM file must be opened for exploitation. The provided CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, reflecting high impact once triggered.
Defensive priority
High
Recommended defensive actions
- Update MicroDicom DICOM Viewer to version 2025.2 or later, per the vendor remediation in the advisory.
- Treat DCM files from untrusted or external sources as potentially malicious and limit where they can be opened.
- Use least-privilege workstation practices and restrict software exposure on systems that do not need DICOM viewing.
- Verify remediation across affected endpoints and keep the CISA advisory and vendor download guidance available for follow-up.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory ICSMA-25-121-01 (published 2025-05-01, revised 2025-05-06) and the vendor remediation noted there. The supplied enrichment does not list a KEV entry or ransomware campaign use.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-35975 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-35975
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-35975 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-35975
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-121-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-121-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.