Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
CVE-2023-34296

8.8HIGH

Key Information:

Vendor

Sante

Vendor
CVE Published:
3 May 2024

What is CVE-2023-34296?

This vulnerability in Sante DICOM Viewer Pro stems from the improper validation of user-supplied data during the parsing of DCM files. Attackers can exploit this flaw to perform an Out-Of-Bounds Write, potentially leading to remote code execution. In order for the attack to be successful, user interaction is necessary, as it requires the target to open a specially crafted file or visit a malicious web page. The flaw creates an opportunity for remote attackers to execute arbitrary code within the context of the vulnerable application, posing significant security risks to users.

Affected Version(s)

DICOM Viewer Pro 12.2.3.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.