MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
Vulnerability
A stack-based buffer overflow vulnerability allowing remote code execution has been identified in MedDream PACS Server. This issue arises from improper validation of user-supplied data lengths when parsing DICOM files, leading to arbitrary code execution in the context of the service account. Notably, authentication is not required to exploit this vulnerability.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the affected system, with the executed code running under the service account's privileges.
Remediation
Users can upgrade to MedDream PACS Server version 7.3.5.860 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
