Researchers reported a one-click remote code execution path affecting the Windows-based IDIS Cloud Manager (ICM) Viewer used to monitor IDIS IP camera deployments. The issue is tracked as CVE-2025-12556 (reported CVSS 8.7) and could allow an attacker to achieve full compromise of the victim workstation by luring a user into clicking a specially crafted link, effectively turning surveillance management tooling into an initial access vector for broader enterprise intrusion.
Technical details indicate the attack chain involves a local Windows service, CWGService.exe, which listens on localhost port 16140 and accepts commands (via a WebSocket interaction) to launch the ICM Viewer with supplied parameters. The service reportedly does not adequately validate the origin of requests or sanitize input arguments, enabling parameter injection that can lead to code execution on the host running ICM Viewer. The vulnerability was attributed to research by Claroty/Team82, and is relevant to organizations using IDIS’s cloud-managed surveillance ecosystem (cameras/NVRs/VMS integrated through ICM).

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CISA assigned or published guidance for CVE-2025-12556, rating it CVSS 8.7 and warning that the flaw could enable full compromise of affected Windows workstations. The agency advised users to upgrade to version 1.7.1 or remove the viewer if unnecessary.
Following confirmation of the flaw, IDIS told customers to upgrade ICM Viewer to version 1.7.1 or uninstall the software if upgrading was not possible. This guidance served as the vendor's mitigation and response to the vulnerability.
Claroty publicly released research showing how a malicious webpage could connect to CWGService.exe on localhost:16140 and inject Chromium flags such as --utility-cmd-prefix to achieve code execution on the host. The publication established the attack as a one-click client-side compromise path affecting ICM Viewer users.
Claroty Team82 identified a one-click remote code execution vulnerability in the Windows-based IDIS Cloud Manager Viewer caused by unsafe localhost WebSocket handling, a hard-coded key, and unsanitized Chromium/CEF arguments. The issue was disclosed to IDIS and confirmed by the vendor as CVE-2025-12556.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcereddit.com
Open sourceclaroty.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.