
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-5943 is an out-of-bounds write vulnerability (CWE-787) in MicroDicom DICOM Viewer that allows remote attackers to potentially execute arbitrary code on affected systems. It affects DICOM Viewer versions 2025.2 (Build 8154) and prior. The vulnerability was reported by researcher Michael Heinzl to CISA and publicly disclosed on June 10, 2025. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4 base score of 8.6 (High) (CISA Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the bounds of an allocated memory buffer when processing malformed input. Exploitation requires user interaction: a victim must either visit a malicious website or open a specially crafted DICOM file locally, after which a remote attacker can trigger the out-of-bounds write condition. No privileges are required on the part of the attacker, and attack complexity is low. The vulnerability was reported to CISA by researcher Michael Heinzl, though no public proof-of-concept code has been released (CISA Advisory).
Successful exploitation could allow an attacker to execute arbitrary code on the affected system with the privileges of the DICOM Viewer process, resulting in high impacts to confidentiality, integrity, and availability. In healthcare environments, this could compromise the integrity of medical diagnostic imaging data, disrupt clinical workflows, or serve as an entry point for lateral movement within hospital networks. Given the critical infrastructure context (Healthcare and Public Health sector), exploitation could have patient safety implications if imaging systems are disrupted (CISA Advisory).
No known public exploitation of CVE-2025-5943 has been reported to CISA, and no public proof-of-concept exploit code is known to exist at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.175%, indicating a low current probability of exploitation in the wild. Exploitation requires user interaction (opening a malicious file or visiting a malicious website), which somewhat limits opportunistic attack scenarios (CISA Advisory).
cmd.exe, powershell.exe, curl, or other shells/utilities).MicroDicom recommends updating DICOM Viewer to version 2025.3 or later to remediate this vulnerability. As interim mitigations, CISA advises minimizing network exposure for DICOM systems, placing them behind firewalls isolated from business networks, and using VPNs for any required remote access. Organizations should also avoid clicking unsolicited web links or opening unexpected DICOM file attachments, and implement network segmentation for medical imaging infrastructure (CISA Advisory).
CISA published ICS Medical Advisory ICSMA-25-160-01 on June 10, 2025, highlighting the vulnerability's relevance to the Healthcare and Public Health critical infrastructure sector. The UK's NHS Digital also issued a cyber alert (CC-4667) referencing the vulnerability, indicating concern within the healthcare community. Coverage appeared on security news aggregators and forums including Windows Forum and IT Security News, reflecting moderate community interest given the healthcare sector implications (CISA Advisory, NHS Cyber Alert).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."