[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMWHTo3wiy7T7OYGWdjQoBt8bNhgeEVXH5LC8r1Nn9jM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"f70f509e-a530-4a89-90de-f9a2721b20a5","radiant-dicom-viewer-flaw-enables-remote-code-execution-via-malicious-files","6d754195-1e77-4153-bad1-523ebb281b9b","RadiAnt DICOM Viewer Flaw Enables Remote Code Execution via Malicious Files","A critical out-of-bounds write vulnerability in Medixant RadiAnt DICOM viewer (CVE-2026-17264) allows attackers to achieve remote code execution by convincing a user to open a specially crafted DICOM file. This is a classic user-triggered exploit pattern where an unpatched application processes malformed input without proper bounds checking, leading to memory corruption. Medical imaging software is particularly high-risk because DICOM files are routinely shared across healthcare networks, radiology departments, and external providers, giving attackers a plausible delivery vector. The healthcare sector's reliance on legacy and specialized software often delays patching, amplifying the window of exposure. Exploitation could compromise clinical workstations, potentially impacting patient data confidentiality and care continuity.","**Immediate actions:**\n- Upgrade all installations of Medixant RadiAnt DICOM to version 2026.1 or later immediately.\n- Restrict the opening of DICOM files from untrusted or external sources until patching is confirmed.\n- Alert clinical and radiology staff not to open DICOM files received from unexpected or unverified senders.\n\n**Long-term improvements:**\n- Establish a formal software inventory and patch management process specifically covering medical imaging and clinical applications.\n- Implement application whitelisting and sandboxing on clinical workstations to limit the blast radius of file-based exploits.\n- Integrate medical device and clinical software CVEs into your organization's vulnerability management program with defined SLA timelines for critical patches.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tools on radiology workstations to flag anomalous process behavior following file opens.\n- Monitor for unusual outbound network connections from DICOM viewer processes as an indicator of post-exploitation activity.\n- Enable centralized logging of file access and process execution events on systems running medical imaging software.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 9: Email and Web Browser Protections","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST SA-11: Developer Testing and Evaluation (memory safety)","HIPAA Security Rule 45 CFR §164.308(a)(5): Security Awareness and Training","HIPAA Security Rule 45 CFR §164.312(a)(1): Access Control","IEC 62443-2-4: Security Program Requirements for IACS Service Providers","ITIL Change Management: Emergency Change Procedures","published","2026-08-06T18:21:13.406215+00:00","2026-08-06T18:21:13.094+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-medical-advisories\u002Ficsma-26-218-01","medixant-radiant-dicom-6070b1","Medixant RadiAnt DICOM",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]