Sign in
Security Advisory CVE-2026-17264
Overview
  • RadiAnt DICOM Viewer 2026.1 resolves an out-of-bounds write vulnerability. Successful exploitation of this vulnerability could allow an attacker to craft a malicious DICOM file that, when opened by a user, causes the application to crash.
Vulnerability ID
  • CVE-2026-17264
Affected Product and Versions
  • RadiAnt DICOM Viewer
  • All versions prior to 2026.1
Description
  • Opening a specially crafted DICOM file containing malicious JPEG-compressed pixel data can trigger an attacker-controlled heap out-of-bounds write. This vulnerability can cause the application to crash and may, under certain conditions, allow arbitrary code execution. As of this disclosure, no proof of remote code execution (RCE) is known, and the likelihood of successful exploitation for RCE is assessed to be very low.
CVSS Score
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L 4.3 MEDIUM
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N 5.3 MEDIUM
Resolution
  • Users should upgrade to RadiAnt DICOM Viewer 2026.1 or later.
  • As a general security best practice, users should open DICOM files only from trusted sources.
  • Additionally, the application is built with several exploit mitigation technologies enabled, including Control Flow Guard (CFG), Data Execution Prevention (DEP), and Address Space Layout Randomization (ASLR). While these mitigations do not eliminate the vulnerability, they significantly reduce its practical exploitability, particularly for code execution attacks.
Reporter
  • This vulnerability was discovered by banda, oriotie, ax123, jihyeon4725, lacroix, minzu.
Disclosure Timeline
  • Date of First Vendor Contact Attempt: 2026-07-01
  • Date of Vendor Response: 2026-07-01
  • Date of Patch Release: 2026-07-14
  • Disclosure Date: 2026-08-06