PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-35975 MicroDicom CVE debrief

MicroDicom DICOM Viewer is affected by an out-of-bounds write that may allow arbitrary code execution when a user opens a malicious DCM file. CISA published the advisory as ICSMA-25-121-01 on 2025-05-01 and later revised it on 2025-05-06 for typos. MicroDicom’s remediation is to update DICOM Viewer to version 2025.2 or later.

Vendor
MicroDicom
Product
DICOM Viewer
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-05-01
Original CVE updated
2025-05-06
Advisory published
2025-05-01
Advisory updated
2025-05-06

Who should care

Organizations and users running MicroDicom DICOM Viewer, especially healthcare, imaging, and workstation teams that handle DCM files from external or untrusted sources.

Technical summary

The supplied advisory describes an out-of-bounds write in MicroDicom DICOM Viewer with the user interaction condition that a malicious DCM file must be opened for exploitation. The provided CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, reflecting high impact once triggered.

Defensive priority

High

Recommended defensive actions

  • Update MicroDicom DICOM Viewer to version 2025.2 or later, per the vendor remediation in the advisory.
  • Treat DCM files from untrusted or external sources as potentially malicious and limit where they can be opened.
  • Use least-privilege workstation practices and restrict software exposure on systems that do not need DICOM viewing.
  • Verify remediation across affected endpoints and keep the CISA advisory and vendor download guidance available for follow-up.

Evidence notes

This debrief is based on the supplied CISA CSAF advisory ICSMA-25-121-01 (published 2025-05-01, revised 2025-05-06) and the vendor remediation noted there. The supplied enrichment does not list a KEV entry or ransomware campaign use.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-35975 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-35975

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-35975 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-35975

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-121-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-121-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.