CVE-2025-2480

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 345

Summary

CVE-2025-2480 is a newly disclosed vulnerability affecting the Santesoft Sante DICOM Viewer Pro software. This issue allows a local attacker to execute arbitrary code by manipulating a DCM (Digital Imaging and Communications in Medicine) file. The vulnerability is an out-of-bounds write, which occurs when a program attempts to write data beyond the allocated memory space. To exploit this weakness, the attacker must persuade a user to open a maliciously crafted DCM file, potentially through email or a compromised website. This vulnerability poses a significant risk to users of the Santesoft Sante DICOM Viewer Pro and requires immediate attention and patching to mitigate the potential harm.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • eProsima Fast DDS

Affected Vendors

  • eProsima