Rapid7

vulnerability

MicroDicom DICOM Viewer: CVE-2025-2029: Improper Restriction of Operations within the Bounds of a Memory Buffer

Severity
4
CVSS
(AV:L/AC:L/Au:S/C:P/I:P/A:P)
Published
Mar 6, 2025
Added
Apr 15, 2025
Modified
Mar 25, 2026

Description

A vulnerability was found in MicroDicom DICOM Viewer 2025.1 Build 3321. It has been classified as critical. Affected is an unknown function of the file mDicom.exe. The manipulation leads to memory corruption. The attack needs to be approached locally. It is recommended to upgrade the affected component. The vendor quickly confirmed the existence of the vulnerability and fixed it in the latest beta.

Solution

microdicom-dicom-viewer-upgrade-latest
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.