Buffer Overflow Vulnerability in Sante DICOM Viewer Pro by Sante
CVE-2022-24060

3.3LOW

Key Information:

Vendor

Sante

Vendor
CVE Published:
18 February 2022

What is CVE-2022-24060?

This vulnerability permits remote attackers to access sensitive information on installations of Sante DICOM Viewer Pro 11.8.7.0. Successful exploitation requires the victim to visit a malicious webpage or open a compromised file. The underlying issue resides in the DCM file parsing, where malformed input can lead to a read operation beyond the allocated buffer limits. Attackers may combine this vulnerability with other exploits to execute arbitrary code within the affected program's environment.

Affected Version(s)

DICOM Viewer Pro 11.8.7.0

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mat Powell of Trend Micro Zero Day Initiative
.