CVE-2025-2357

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 17, 2025
CWE ID 79

Summary

CVE-2025-2357 is a critical vulnerability affecting DCMTK 3.6.9, specifically the dcmjpls JPEG-LS Decoder component. The issue involves memory corruption, which can be exploited remotely. The attackers can manipulate the code to initiate the vulnerability, and the exploit has already been disclosed to the public. To mitigate this risk, it's strongly recommended to apply the patch with the commit ID 3239a7915 as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share