# Medical Imaging Software RadiAnt DICOM Viewer Carries File-Parsing Flaw With Patient Data Implications
## The Threat
RadiAnt DICOM Viewer — the widely used Windows application for viewing medical imaging files — contains a vulnerability that allows an attacker to trigger an out-of-bounds read by convincing a clinician or technician to open a specially crafted DICOM file. DICOM (Digital Imaging and Communications in Medicine) is the universal standard for storing and transmitting medical images: X-rays, CT scans, MRIs, ultrasounds. Virtually every hospital radiology department and imaging clinic in the world processes DICOM files daily, which makes any parser-level flaw in this software a category worth taking seriously.
The attack vector is local and social-engineering dependent — a threat actor cannot exploit this remotely without interaction. But in healthcare environments, DICOM files routinely travel via USB drives, email attachments, and CD-ROMs handed off from external imaging centers, creating natural delivery channels for a weaponized file. A radiologist, PACS administrator, or technologist opening a file received from an outside facility is a completely routine workflow, not a suspicious one.
The underlying weakness is a memory-handling error during DICOM file parsing. When the application processes certain malformed image metadata fields, it reads beyond the bounds of an allocated buffer. In the best case, this causes a crash — an annoyance in a clinical setting, but recoverable. In a worst case, an attacker with enough control over surrounding memory could leverage this to leak sensitive data or achieve code execution, though the latter would require additional exploitation effort on modern Windows systems.
## Severity and Impact
| Field | Detail |
|---|---|
| CVE | CVE-2025-2550 |
| CVSS Score | 7.8 (High) |
| CVSS Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CWE | CWE-125: Out-of-Bounds Read |
| Attack Vector | Local |
| Attack Complexity | Low |
| User Interaction | Required |
| Authentication | None required |
| Impact | Confidentiality: High / Integrity: High / Availability: High |
The local attack vector drops this below critical, but the High rating on confidentiality, integrity, and availability reflects what a successful exploitation could yield on a workstation that handles protected health information.
## Affected Products
RadiAnt is a standalone Windows application. It does not have server or web components exposed to network attack; exposure requires a user to interact with a malicious file.
## Mitigations
Immediate action:
If updating immediately is not feasible:
Longer-term posture improvements:
## References
---
## HackWire Analysis
The healthcare sector continues to lag on software patching, and DICOM viewer vulnerabilities illustrate exactly why that lag is dangerous. Unlike enterprise software that benefits from centralized MDM enforcement, clinical workstations in radiology are often managed by whoever handles the PACS (Picture Archiving and Communication System), which in smaller facilities may be a single vendor technician who visits quarterly. The time between a patch release and actual deployment on every imaging workstation in a mid-sized regional hospital network can stretch to months — sometimes over a year.
What makes this class of vulnerability particularly uncomfortable for defenders is the legitimacy of the delivery mechanism. Security teams train users to distrust unexpected email attachments. But a radiologist receiving a DICOM file from an external imaging center is not doing anything wrong — that is the workflow. Weaponizing a legitimate clinical process is a hallmark of effective healthcare-sector targeting, and groups focused on medical data exfiltration know this.
The broader pattern here is persistent: DICOM parsers across multiple vendors have accumulated file-handling vulnerabilities for years, largely because medical imaging software grew up in an era when security was an afterthought and DICOM files were assumed to come only from trusted medical devices on closed networks. That assumption stopped being true the moment imaging data started moving over general-purpose networks, email, and physical media — which is to say, a long time ago.
For healthcare security teams, this advisory is a forcing function to audit which workstations are running RadiAnt and which version. If you do not have a software inventory that can answer that question in under ten minutes, the RadiAnt gap is the smallest of your problems.
— HackWire Editorial
---
## Related Coverage