CVE-2025-25475

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 18, 2025
Updated: Feb 20, 2025
CWE ID 476

Summary

CVE-2025-25475 is a denial-of-service vulnerability affecting DCMTK v3.6.9+ DEV. The issue lies within the /libsrc/dcrleccd.cc component and arises from a NULL pointer dereference. An adversary can exploit this flaw by crafting a malicious DICOM file to trigger the NULL pointer dereference and cause the system to crash, resulting in a denial-of-service condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share