MicroDicom DICOM Viewer drew back-to-back advisories. ICSMA-25-121-01 in May, out-of-bounds write and read, both 8.8. Then ICSMA-25-160-01 in June, another out-of-bounds write, CVE-2025-5943 at 8.8. Michael Heinzl again.
An out-of-bounds write or read is a failure of a program to police the edges of its own memory. A parser walks a file expecting each field to describe a length and a type it can trust, and when a crafted field lies about its size, the code reads past the buffer it allocated or writes beyond it. Absent automatic bounds checking, that stray access is the seed of a crash or, in the write case, of attacker-controlled corruption.
Patch 2025.2, then patch 2025.3, for the same kind of bug in the same parser. That cadence says the fixes addressed instances, not the underlying pattern. Free and widely used DICOM viewers are quietly everywhere in clinical environments, so a crafted study or a malicious website reaches a lot of them.
The DICOM format is old, sprawling and permissive, with a long list of encodings and optional fields a viewer must accept from whatever source sends them. That breadth is what makes the parser a recurring soft spot, since every branch of the format is another path an adversary can probe. Because a viewer opens files arriving from imaging systems, mail and the web, hostile input does not need an insider to deliver it.
Repeated memory-corruption findings in one product do not call for another point fix. They call for hardening the parser: memory-safe handling, fuzzing in CI, and treating every field of the format as hostile.
The workstation that renders a study is often the same machine a radiologist uses to read, dictate and sign off, so code execution there reaches into the reading workflow and the credentials sitting on the desk. A viewer subverted by the very files it exists to display inverts the trust a clinician places in the tool. The disruption need not be dramatic to matter, since a reader who cannot open a study cannot report on it.