Sensitive Information Disclosure in Sante DICOM Viewer Pro by Intuitive
CVE-2022-24061

3.3LOW

Key Information:

Vendor

Sante

Vendor
CVE Published:
18 February 2022

What is CVE-2022-24061?

This vulnerability allows remote attackers to expose sensitive information on affected installations of Sante DICOM Viewer Pro 11.8.7.0. The flaw arises during the parsing of DCM files due to insufficient validation of object existence before performing operations on it. In such scenarios, user interaction is required, as the target must visit a malicious website or open a compromised file. Attackers could exploit this weakness in combination with other vulnerabilities to execute arbitrary code within the current process, enhancing the threat landscape for users.

Affected Version(s)

DICOM Viewer Pro 11.8.7.0

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mat Powell of Trend Micro Zero Day Initiative
.