CVE-2025-2480: Santesoft Sante DICOM Viewer Pro Out-of-bounds Write
Santesoft Sante DICOM Viewer Pro is vulnerable to an out-of-bounds write, which requires a user to open a malicious DCM file, resulting in execution of arbitrary code by a local attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Santesoft Sante DICOM Viewer Proto a version that resolves this vulnerability.Fixed in v14.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2480?
CVE-2025-2480 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-2480?
To mitigate CVE-2025-2480, ensure you are using the latest version of Santesoft Sante DICOM Viewer Pro, which contains the necessary security patches.
Who is affected by CVE-2025-2480?
Users of Santesoft Sante DICOM Viewer Pro are affected by CVE-2025-2480 if they open malicious DCM files.
What type of vulnerability is CVE-2025-2480?
CVE-2025-2480 is an out-of-bounds write vulnerability that allows local attackers to execute arbitrary code.
Can CVE-2025-2480 be exploited remotely?
No, CVE-2025-2480 requires local access as it is triggered by opening a malicious DCM file.