CVE-2025-2029

MEDIUM

MicroDicom DICOM Viewer 2025.1 Build 3321 - Memory Corruption

Title source: llm
STIX 2.1

Description

A vulnerability was found in MicroDicom DICOM Viewer 2025.1 Build 3321. It has been classified as critical. Affected is an unknown function of the file mDicom.exe. The manipulation leads to memory corruption. The attack needs to be approached locally. It is recommended to upgrade the affected component. The vendor quickly confirmed the existence of the vulnerability and fixed it in the latest beta.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.298770
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.298770
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.506579
Various Sources patch
https://www.microdicom.com/beta.html

Scores

CVSS v3 5.3
EPSS 0.0016
EPSS Percentile 5.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-119
Status published
Products (1)
MicroDicom/DICOM Viewer 2025.1 Build 3321
Published Mar 06, 2025
Tracked Since Feb 18, 2026