Medixant RadiAnt DICOM
Summary
Successful exploitation of a vulnerability in Medixant RadiAnt DICOM versions prior to 2025.2 could allow an attacker to remotely execute arbitrary code by opening a specially crafted DICOM file. The vulnerability involves an out-of-bounds write within the application when processing malicious JPEG-compressed pixel data.
IFF Assessment
The article details a vulnerability that could allow for remote code execution, posing a direct threat to defenders.
Severity
The CVSS v3.1 score of 4.3 indicates a Medium severity vulnerability, with an attack vector of Network and privileges required of None, but the impact on integrity and availability is limited, and exploit mitigation mechanisms are noted.
Defender Context
This alert highlights an out-of-bounds write vulnerability in a widely used DICOM viewer within the healthcare sector. Defenders should ensure that systems running Medixant RadiAnt DICOM are updated to version 2026.1 to mitigate the risk of remote code execution via malformed DICOM files.