CVE-2025-12556
8.8IDIS · ICM Viewer
IDIS ICM Viewer is affected by an argument injection vulnerability that allows an authenticated attacker to execute arbitrary code within the host machine context.
Executive summary
An argument injection vulnerability in IDIS ICM Viewer version 1.6.0.10 poses a significant risk of remote code execution for authenticated users.
Vulnerability
The software fails to properly neutralize argument delimiters, leading to an argument injection vulnerability (CWE-88). This flaw allows an authenticated attacker to manipulate command-line arguments to achieve arbitrary code execution.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute code with the privileges of the application, potentially leading to a full system compromise. Given the CVSS score of 8.8, this vulnerability represents a high risk to the confidentiality, integrity, and availability of host systems. Organizations relying on this software for security or management operations face significant operational disruption and data exposure risks if their environments are compromised.
Remediation
Immediate Action: All users must upgrade to version 1.7.1 by following the instructions provided at the official IDIS ICM portal. If the software is no longer required, it should be uninstalled immediately to eliminate the attack surface.
Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process execution patterns or unusual command-line arguments originating from the ICM Viewer process.
Compensating Controls: Ensure that the host machine is isolated via network segmentation and that the application runs with the minimum necessary operating system privileges to limit the impact of a potential compromise.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
The severity of this vulnerability, combined with the potential for arbitrary code execution, mandates immediate attention. Administrators must prioritize upgrading to version 1.7.1 as defined by the vendor. Delaying this update exposes the host environment to a critical security failure, and prompt remediation is the only effective way to neutralize this risk.
Sources
Originally found and disclosed by Vera Mens and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.