Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Argument injection leading to 1-click RCE in IDIS Cloud Manager (ICM) Viewer for Windows

IdentifiersCVE-2025-12556CWE-88· Improper Neutralization of…

CVE-2025-12556 is an argument injection vulnerability in IDIS Cloud Manager (ICM) Viewer for Windows. The ICM Web Portal (web UI) communicates over a local WebSocket endpoint (ws://localhost:16140) to a Windows service/launcher component (CWGService.exe), which then starts the Chromium/CEF-based viewer (WCMViewer.exe) with command-line arguments (e.g., URL, token, mode, language) derived from the WebSocket message. Because CWGService.exe does not validate the WebSocket origin, uses a constant/hard-coded encryption key for messages, and does not sanitize/validate the parameters before launching WCMViewer.exe (and WCMViewer.exe forwards them to CEF), an attacker can craft a malicious webpage with JavaScript that sends a valid encrypted WebSocket message to localhost:16140 and inject additional Chromium command-line flags (notably --utility-cmd-prefix). This enables escaping the browser sandbox and executing arbitrary code on the host with a single user action (visiting/clicking a link).

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation results in arbitrary code execution on the victim Windows host in the context of the ICM Viewer/launcher process. The content notes this can enable full workstation compromise, including data theft, installation of additional malware, and lateral movement within the victim network (including to other surveillance-related endpoints).

Mitigation

If you can’t patch tonight, do this now.

If the viewer is not required, uninstall it. Otherwise, reduce exposure by preventing untrusted web content from reaching the affected workstation (e.g., restrict browsing from surveillance management workstations) and limit/monitor local access to the CWGService.exe WebSocket listener on localhost:16140 until the upgrade to 1.7.1 is completed.

Remediation

Patch, then assume compromise.

Upgrade IDIS ICM Viewer to version 1.7.1 (vendor-recommended fixed version). If upgrading is not possible, uninstall the ICM Viewer software.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

ACTIVITY FEED

Recent activity

9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
Feb 2, 2026
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats

Unknown (listed as a trending CVE affecting IDIS IP cameras; no technical details provided in the content).

Read more
cyber security newsNews
Jan 29, 2026
Critical IDIS IP Cameras One-Click Vulnerability Leads to full Compromise of Victim’s Computer

Remote code execution in the Windows-based IDIS Cloud Manager (ICM) Viewer via a local WebSocket-exposed service (CWGService.exe on port 16140) that fails to validate origin/sanitize inputs, enabling injection of Chromium Embedded Framework command-line flags (e.g., --utility-cmd-prefix) to execute arbitrary commands when a user visits a malicious webpage/clicks a link.

Read more
claroty team82News
Jan 27, 2026
New Architecture, New Risks: One-Click to Pwn IDIS IP Cameras | Claroty

A 1-click remote code execution vulnerability in the IDIS Cloud Manager (ICM) Viewer Windows client chain: a local WebSocket service (CWGService.exe) accepts attacker-originated requests (no origin validation), uses a constant encryption key, and fails to sanitize parameters, allowing command-line/Chromium-flag injection into WCMViewer.exe (CEF/Chromium) and resulting in arbitrary code execution on the host.

Read more
govinfosecurityNews
Jan 28, 2026
Idis Surveillance Management Software Vulnerable to Hacking

A critical injection flaw in Idis ICM Viewer (a Chromium-based web client) where unsanitized inputs/arguments are passed to the Chromium Embedded Framework, enabling abuse of Chromium command-line flags to escape the browser sandbox and achieve arbitrary code execution on the local host (one-click via malicious link).

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.