CVE-2025-12556

8.8

IDIS · ICM Viewer

IDIS ICM Viewer is affected by an argument injection vulnerability that allows an authenticated attacker to execute arbitrary code within the host machine context.

Executive summary

An argument injection vulnerability in IDIS ICM Viewer version 1.6.0.10 poses a significant risk of remote code execution for authenticated users.

Vulnerability

The software fails to properly neutralize argument delimiters, leading to an argument injection vulnerability (CWE-88). This flaw allows an authenticated attacker to manipulate command-line arguments to achieve arbitrary code execution.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute code with the privileges of the application, potentially leading to a full system compromise. Given the CVSS score of 8.8, this vulnerability represents a high risk to the confidentiality, integrity, and availability of host systems. Organizations relying on this software for security or management operations face significant operational disruption and data exposure risks if their environments are compromised.

Remediation

Immediate Action: All users must upgrade to version 1.7.1 by following the instructions provided at the official IDIS ICM portal. If the software is no longer required, it should be uninstalled immediately to eliminate the attack surface.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process execution patterns or unusual command-line arguments originating from the ICM Viewer process.

Compensating Controls: Ensure that the host machine is isolated via network segmentation and that the application runs with the minimum necessary operating system privileges to limit the impact of a potential compromise.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

The severity of this vulnerability, combined with the potential for arbitrary code execution, mandates immediate attention. Administrators must prioritize upgrading to version 1.7.1 as defined by the vendor. Delaying this update exposes the host environment to a critical security failure, and prompt remediation is the only effective way to neutralize this risk.

Sources

Originally found and disclosed by Vera Mens and Noam Moshe of Claroty Team82 reported this vulnerability to CISA., per the CVE Program record.