Medixant RadiAnt DICOM Out-of-Bounds Write Vulnerability
Medixant RadiAnt DICOM versions 2025.2 and earlier are vulnerable to a heap out-of-bounds write flaw that may lead to arbitrary code execution when processing maliciously crafted DICOM files.
Medixant RadiAnt DICOM is a medical imaging software widely used within the Healthcare and Public Health sector for viewing DICOM files. A vulnerability, identified as CVE-2026-17264, exists in versions 2025.2 and earlier of the application. The flaw is caused by improper handling of JPEG-compressed pixel data within a DICOM file, leading to a heap out-of-bounds write (CWE-787). An attacker can leverage this by delivering a specially crafted file to a user. While the software employs modern exploit mitigations like Control Flow Guard (CFG), Data Execution Prevention (DEP), and Address Space Layout Randomization (ASLR), successful exploitation remains a risk, potentially resulting in application crashes or remote code execution. This vulnerability is significant for clinical environments where the integrity and availability of diagnostic imaging software are paramount.
Impact
The vulnerability affects the Healthcare and Public Health sector globally. If successfully exploited, an attacker could force the application to crash, disrupting medical diagnostic workflows, or potentially gain arbitrary code execution on the workstation where the DICOM file is opened. There are no reports of active exploitation in the wild as of August 2026.
Recommendation
- Update Medixant RadiAnt DICOM to version 2026.1 immediately to patch CVE-2026-17264.
- Enforce a policy to open DICOM files only from trusted and verified sources to reduce the risk of handling malicious content.
- Minimize network exposure for workstations running medical imaging software by isolating them from general business networks and the internet.
Immediate actions
Upgrade RadiAnt DICOM to version 2026.1