Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-34295
8.8HIGH
What is CVE-2023-34295?
A remote code execution vulnerability exists in the Sante DICOM Viewer Pro due to improper validation during the parsing of DCM files. This flaw allows attackers to exploit the issue by crafting malicious files or links. When a user visits a compromised webpage or opens a malicious file, the lack of safeguards permits attackers to write past the boundaries of allocated memory, enabling them to execute arbitrary code within the context of the application. Proper measures should be taken to ensure that software remains updated and that users exercise caution with untrusted files or web content.
Affected Version(s)
DICOM Viewer Pro 12.2.3.0