QID 379442
Date Published: 2024-03-05
QID 379442: MicroDicom DICOM Viewer Multiple Vulnerabilities
CVE-2024-22100: MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior are affected by a heap-based buffer overflow vulnerability, which could allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. A user must open a malicious DCM file in order to exploit the vulnerability.
CVE-2024-25578: MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior contain a lack of proper validation of user-supplied data, which could result in memory corruption within the application.
Affected Versions:
MicroDicom DICOM Viewer versions prior to 2024.1
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of MicroDicom DICOM Viewer by checking the fileversion of 'mDicom.exe'. Please note that this QID will only detect installations done via an Installer.
Successful exploitation of these vulnerabilities could allow an attacker to cause memory corruption issues leading to execution of arbitrary code.
- ICSMA-24-060-01 -
www.cisa.gov/news-events/ics-medical-advisories/icsma-24-060-01
CVEs related to QID 379442
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSMA-24-060-01 |
|