Team82 Logo Claroty
High Threat

CVE-2025-12556

CWE-88 IMPROPER NEUTRALIZATION OF ARGUMENT DELIMITERS IN A COMMAND ('ARGUMENT INJECTION'):

An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary code within the context of the host machine.

IDIS provided the following mitigations:

  • Users who continue to use the ICM Viewer, they must access https://icm.idisglobal.com and follow the instructions provided to upgrade to version v1.7.1. IDIS requires all users to upgrade to v1.7.1. Failure to do so will render the ICM Viewer unusable.

  • For those who do not use the ICM Viewer: They must immediately uninstall the program.

Risk Information

CVE ID

CVE-2025-12556

Vendor

IDIS

Product

ICM Viewer

CVSS v3

8.8


Disclosure Policy

Team82 is committed to privately reporting vulnerabilities to affected vendors in a coordinated, timely manner in order to ensure the safety of the cybersecurity ecosystem worldwide. To engage with the vendor and research community, Team82 invites you to download and share our Coordinated Disclosure Policy. Team82 will adhere to this reporting and disclosure process when we discover vulnerabilities in products and services.

Public Email & PGP Key

Team82 has also made its public PGP Key available for the vendor and research community to securely and safely exchange vulnerability and research information with us.

Claroty
LinkedIn Twitter YouTube Facebook