CVE-2025-5943
MicroDicom DICOM Viewer vulnerability analysis and mitigation

Overview

CVE-2025-5943 is an out-of-bounds write vulnerability (CWE-787) in MicroDicom DICOM Viewer that allows remote attackers to potentially execute arbitrary code on affected systems. It affects DICOM Viewer versions 2025.2 (Build 8154) and prior. The vulnerability was reported by researcher Michael Heinzl to CISA and publicly disclosed on June 10, 2025. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4 base score of 8.6 (High) (CISA Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), meaning the application writes data beyond the bounds of an allocated memory buffer when processing malformed input. Exploitation requires user interaction: a victim must either visit a malicious website or open a specially crafted DICOM file locally, after which a remote attacker can trigger the out-of-bounds write condition. No privileges are required on the part of the attacker, and attack complexity is low. The vulnerability was reported to CISA by researcher Michael Heinzl, though no public proof-of-concept code has been released (CISA Advisory).

Impact

Successful exploitation could allow an attacker to execute arbitrary code on the affected system with the privileges of the DICOM Viewer process, resulting in high impacts to confidentiality, integrity, and availability. In healthcare environments, this could compromise the integrity of medical diagnostic imaging data, disrupt clinical workflows, or serve as an entry point for lateral movement within hospital networks. Given the critical infrastructure context (Healthcare and Public Health sector), exploitation could have patient safety implications if imaging systems are disrupted (CISA Advisory).

Exploitability

No known public exploitation of CVE-2025-5943 has been reported to CISA, and no public proof-of-concept exploit code is known to exist at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.175%, indicating a low current probability of exploitation in the wild. Exploitation requires user interaction (opening a malicious file or visiting a malicious website), which somewhat limits opportunistic attack scenarios (CISA Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets running MicroDicom DICOM Viewer versions 2025.2 (Build 8154) or earlier, particularly within healthcare organizations that use DICOM imaging workflows.
  2. Craft malicious payload: Create a specially crafted DICOM file or malicious web page designed to trigger the out-of-bounds write condition in the DICOM Viewer's file parsing or rendering logic.
  3. Deliver payload: Deliver the malicious DICOM file via email attachment, file share, or a malicious website — leveraging social engineering to convince the target user to open the file or visit the URL.
  4. Trigger vulnerability: When the victim opens the malicious DICOM file or visits the malicious website with DICOM Viewer active, the out-of-bounds write is triggered in the application's memory space.
  5. Achieve code execution: Exploit the memory corruption to redirect execution flow and run arbitrary code with the privileges of the DICOM Viewer process, potentially enabling persistence, data exfiltration, or further lateral movement within the network (CISA Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the MicroDicom DICOM Viewer process (e.g., cmd.exe, powershell.exe, curl, or other shells/utilities).
  • File System: Unusual files written to directories accessible by the DICOM Viewer process; unexpected executables or scripts appearing in temp directories or the application's working directory.
  • Network: Unexpected outbound network connections originating from the DICOM Viewer process to external or unknown IP addresses following the opening of a DICOM file.
  • Logs: Application crash logs or Windows Event Log entries indicating memory access violations or abnormal termination of the DICOM Viewer process; security logs showing unusual process creation events associated with the DICOM Viewer parent process.

Mitigation and workarounds

MicroDicom recommends updating DICOM Viewer to version 2025.3 or later to remediate this vulnerability. As interim mitigations, CISA advises minimizing network exposure for DICOM systems, placing them behind firewalls isolated from business networks, and using VPNs for any required remote access. Organizations should also avoid clicking unsolicited web links or opening unexpected DICOM file attachments, and implement network segmentation for medical imaging infrastructure (CISA Advisory).

Community reactions

CISA published ICS Medical Advisory ICSMA-25-160-01 on June 10, 2025, highlighting the vulnerability's relevance to the Healthcare and Public Health critical infrastructure sector. The UK's NHS Digital also issued a cyber alert (CC-4667) referencing the vulnerability, indicating concern within the healthcare community. Coverage appeared on security news aggregators and forums including Windows Forum and IT Security News, reflecting moderate community interest given the healthcare sector implications (CISA Advisory, NHS Cyber Alert).

Additional resources


SourceThis report was generated using AI

Related MicroDicom DICOM Viewer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-5943HIGH8.6
  • MicroDicom DICOM Viewer logoMicroDicom DICOM Viewer
  • cpe:2.3:a:microdicom:dicom_viewer
NoNoJun 10, 2025
CVE-2025-36521HIGH8.6
  • MicroDicom DICOM Viewer logoMicroDicom DICOM Viewer
  • cpe:2.3:a:microdicom:dicom_viewer
NoNoMay 01, 2025
CVE-2025-35975HIGH8.6
  • MicroDicom DICOM Viewer logoMicroDicom DICOM Viewer
  • cpe:2.3:a:microdicom:dicom_viewer
NoNoMay 01, 2025
CVE-2024-33606HIGH8.6
  • MicroDicom DICOM Viewer logoMicroDicom DICOM Viewer
  • cpe:2.3:a:microdicom:dicom_viewer
NoYesJun 11, 2024
CVE-2025-1002MEDIUM5.7
  • MicroDicom DICOM Viewer logoMicroDicom DICOM Viewer
  • cpe:2.3:a:microdicom:dicom_viewer
NoNoFeb 10, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management