A critical argument injection vulnerability, tracked as CVE-2025-12556, was identified in the IDIS ICM Viewer software. This flaw allows remote attackers to execute arbitrary code on affected systems by exploiting improper neutralization of argument delimiters in command execution. The vulnerability is rated with a CVSS v3.1 base score of 8.8 and a CVSS v4 score of 8.7, indicating high severity and significant risk to organizations using the affected product.
The vulnerability specifically impacts ICM Viewer version v1.6.0.10, and exploitation could compromise the host machine's security. IDIS has responded by requiring all users to upgrade to version v1.7.1 to mitigate the risk, warning that failure to update will render the software unusable. CISA has also issued an advisory urging immediate action, including uninstalling the program if it is not in use, to prevent potential exploitation in critical infrastructure environments worldwide.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-12556 was publicly listed as an argument injection vulnerability in IDIS ICM Viewer. The CVE publication provided a distinct identifier and classified the issue as high severity.
CISA released ICS advisory ICSA-25-308-05 covering a security issue affecting IDIS ICM Viewer. The advisory marks the public disclosure of the vulnerability affecting the product.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.