First published: Fri Mar 01 2024(Updated: )
MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by a heap-based buffer overflow vulnerability, which could allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. A user must open a malicious DCM file in order to exploit the vulnerability.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
MicroDicom DICOM Viewer | <2023.3 (Build 9342) | |
<2024.1 |
MicroDicom has provided a fix and recommends users upgrade to 2024.1 https://www.microdicom.com/ . For additional assistance, contact MicroDicom https://www.microdicom.com/contacts.html directly
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22100 has a high severity due to its potential to allow arbitrary code execution.
To fix CVE-2024-22100, update MicroDicom DICOM Viewer to a version later than 2023.3 (Build 9342).
MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by CVE-2024-22100.
CVE-2024-22100 can be exploited by opening a malicious DCM file in the affected versions of the DICOM Viewer.
Users of MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and earlier should be concerned about CVE-2024-22100.