First published: Thu May 01 2025(Updated: )
MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open a malicious DCM file for exploitation.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
MicroDicom DICOM Viewer |
MicroDicom recommends user update DICOM Viewer to version 2025.2 https://www.microdicom.com/downloads.html or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-36521 has been classified with a high severity due to the potential for memory corruption.
To mitigate CVE-2025-36521, users should avoid opening untrusted DCM files and ensure their MicroDicom DICOM Viewer software is updated to the latest version.
CVE-2025-36521 may allow an attacker to execute arbitrary code by exploiting the out-of-bounds read vulnerability.
Exploitation of CVE-2025-36521 requires user interaction, as the user must open a specifically crafted malicious DCM file.
CVE-2025-36521 specifically affects the MicroDicom DICOM Viewer application.