Impact
This vulnerability is an out‑of‑bounds write on the heap that occurs when a RadiAnt DICOM Viewer opens a maliciously crafted DICOM file containing JPEG‑compressed pixel data. Classified as CWE‑787, it can allow an attacker to execute arbitrary code on the host, compromising confidentiality, integrity, and availability.
Affected Systems
The issue affects Medixant RadiAnt DICOM Viewer installations prior to version 2026.1; users should verify that they are running 2026.1 or later to receive the fix.
Risk and Exploitability
The CVSS base score of 5.3 indicates medium severity and no EPSS data is available to gauge current exploitation activity. The flaw is not listed in the CISA KEV catalog. Exploitation requires a victim to open a specially crafted DICOM file, making it a local user‑level threat. The viewer is compiled with Control Flow Guard, DEP, and ASLR, which reduce the likelihood of a successful exploit. Overall exposure is moderate, especially for shared or unattended installations that may accept arbitrary DICOM files.
OpenCVE Enrichment