CVE-2024-52333
CVSS 3.1 Score 8.4 of 10 (high)
Details
Published Jan 13, 2025
CWE ID 119
Summary
CVE-2024-52333 is a newly identified vulnerability affecting the OFFIS DCMTK 3.6.8 version. This issue involves an improper array index validation in the determineMinMax function. A maliciously crafted DICOM file can exploit this vulnerability, leading to an out-of-bounds write. An attacker can take advantage of this issue by providing a specially designed DICOM file, which can result in unintended data modifications or even system crashes. To mitigate this risk, users are advised to update their DCMTK software as soon as a patch becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.