First published: Thu Mar 20 2025(Updated: )
Santesoft Sante DICOM Viewer Pro is vulnerable to an out-of-bounds write, which requires a user to open a malicious DCM file, resulting in execution of arbitrary code by a local attacker.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Sante DICOM Viewer Pro |
Santesoft released an updated version of their product and recommends updating Sante DICOM Viewer Pro to v14.2.0 https://santesoft.com/win/sante-dicom-viewer-pro/download.html or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2480 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2025-2480, ensure you are using the latest version of Santesoft Sante DICOM Viewer Pro, which contains the necessary security patches.
Users of Santesoft Sante DICOM Viewer Pro are affected by CVE-2025-2480 if they open malicious DCM files.
CVE-2025-2480 is an out-of-bounds write vulnerability that allows local attackers to execute arbitrary code.
No, CVE-2025-2480 requires local access as it is triggered by opening a malicious DCM file.