DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of DICOM Viewer. User interaction is required to exploit the vulnerability in that the user must either visit a malicious website or open a malicious DICOM file locally.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17756 | MicroDicom DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of DICOM Viewer. User interaction is required to exploit the vulnerability in that the user must either visit a malicious website or open a malicious DICOM file locally. |
Solution
MicroDicom recommends users update DICOM Viewer to version 2025.3 https://www.microdicom.com/downloads.html or later.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MicroDicom DICOM Viewer suffers from an out-of-bounds write vulnerability. Remote attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of DICOM Viewer. User interaction is required to exploit the vulnerability in that the user must either visit a malicious website or open a malicious DICOM file locally. | |
| Title | MicroDicom DICOM Viewer Out-of-bounds Write | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-06-11T14:39:58.540Z
Reserved: 2025-06-09T16:39:58.384Z
Link: CVE-2025-5943
Updated: 2025-06-11T14:39:54.644Z
Status : Awaiting Analysis
Published: 2025-06-10T18:15:33.020
Modified: 2025-06-12T16:06:29.520
Link: CVE-2025-5943
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:51:41Z
EUVD