Malicious DICOM File Can Trigger Information Disclosure or Arbitrary Code Execution
CVE-2024-1453
7.8HIGH
What is CVE-2024-1453?
In Sante DICOM Viewer Pro versions 14.0.3 and earlier, a vulnerability exists that requires the user to open a specially crafted DICOM file. This action may enable a local attacker to leverage the flaw to disclose sensitive information or execute arbitrary code on the affected system. Users are advised to be cautious while handling DICOM files from untrusted sources and maintain updated software to mitigate associated risks.
Affected Version(s)
Sante DICOM Viewer Pro 0 <= 14.0.3
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Heinzl reported this vulnerability to CISA.