First published: Mon Mar 11 2024(Updated: )
In Santesoft Sante FFT Imaging versions 1.4.1 and prior once a user opens a malicious DCM file on affected FFT Imaging installations, a local attacker could perform an out-of-bounds write, which could allow for arbitrary code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Santesoft Sante FFT Imaging | <1.4.1 | |
Santesoft Sante FFT Imaging | <1.4.2 |
Santesoft released an updated version of their product and recommends users update Sante FFT Imaging to v1.4.2 https://santesoft.com/win/sante-fft-imaging/download.html or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1696 is considered critical due to its potential for arbitrary code execution.
To fix CVE-2024-1696, upgrade Santesoft Sante FFT Imaging to version 1.4.2 or later.
CVE-2024-1696 affects Santesoft Sante FFT Imaging versions 1.4.1 and prior.
CVE-2024-1696 is an out-of-bounds write vulnerability that can lead to arbitrary code execution.
If CVE-2024-1696 is exploited, a local attacker could execute arbitrary code on the affected system.