Out-of-Bounds Write Vulnerability in Santesoft Sante DICOM Viewer Pro
CVE-2025-2480

8.4HIGH

Key Information:

Vendor

Santesoft

Vendor
CVE Published:
20 March 2025

What is CVE-2025-2480?

Santesoft Sante DICOM Viewer Pro is susceptible to an out-of-bounds write vulnerability that arises when a user opens a specially crafted malicious DCM file. This condition can lead to the execution of arbitrary code by a local attacker, potentially compromising the security and functionality of the system. It is crucial for users to ensure their software is updated to the latest version to mitigate this risk.

Affected Version(s)

Sante DICOM Viewer Pro 0 <= 14.1.2

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported this vulnerability to CISA.
.