PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-22100 MicroDicom CVE debrief

A heap-based buffer overflow vulnerability in MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior allows arbitrary code execution when a user opens a malicious DCM file. The vulnerability was disclosed by CISA on February 29, 2024, with a CVSS 3.1 score of 7.8 (HIGH). The attack vector is local, requiring user interaction to open a crafted file, but successful exploitation grants high impact across confidentiality, integrity, and availability.

Vendor
MicroDicom
Product
DICOM Viewer
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-29
Original CVE updated
2024-02-29
Advisory published
2024-02-29
Advisory updated
2024-02-29

Who should care

Healthcare organizations, medical imaging departments, radiology practices, and any entities using MicroDicom DICOM Viewer for diagnostic imaging should prioritize patching. Security teams in healthcare environments should assess exposure and implement user awareness training given the user-interaction requirement for exploitation.

Technical summary

The vulnerability exists in MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and earlier. A heap-based buffer overflow can be triggered when parsing a maliciously crafted DCM (DICOM) file. The CVSS 3.1 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H indicates local attack vector, low attack complexity, no privileges required, user interaction required, and high impact on confidentiality, integrity, and availability. Successful exploitation allows arbitrary code execution in the context of the application.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade MicroDicom DICOM Viewer to version 2024.1 or later to remediate this vulnerability
  • Train users to avoid opening DCM files from untrusted sources and to verify file origins before opening
  • Implement application whitelisting and least-privilege execution policies to limit impact of potential exploitation
  • Consider network segmentation for systems handling medical imaging data to contain potential compromise
  • Review and apply CISA's ICS recommended practices for defense-in-depth strategies

Evidence notes

CISA published advisory ICSMA-24-060-01 on February 29, 2024, identifying this heap-based buffer overflow in MicroDicom DICOM Viewer. The vulnerability requires local access and user interaction (opening a malicious DCM file) but results in complete system compromise. MicroDicom has released version 2024.1 as a fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-22100 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-22100

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-22100 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-22100

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsma-24-060-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-060-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.