PT-2024-22977 · Unknown · Sonicdicom Media Viewer

Taihei Shimamine

·

Published

2024-03-28

·

Updated

2024-10-31

·

CVE-2024-29734

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SonicDICOM Media Viewer versions 2.3.2 and earlier
Description An uncontrolled search path element issue exists, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.
Recommendations For SonicDICOM Media Viewer versions 2.3.2 and earlier, consider disabling the loading of Dynamic Link Libraries until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2024-29734

Affected Products

Sonicdicom Media Viewer