Out‑of‑Bounds Write (CVE‑2026‑17264) in Medixant RadiAnt DICOM Viewer Allows Remote Code Execution
What It Is — A heap out‑of‑bounds write triggered by a maliciously crafted DICOM file can let an attacker execute arbitrary code on systems running Medixant RadiAnt DICOM Viewer ≤ 2025.2.
Exploitability — CVSS v3 4.3 (Low). Exploits exist in the wild; the vendor notes that built‑in mitigations (CFG, DEP, ASLR) reduce practical exploitability, but successful exploitation remains possible.
Affected Products — Medixant RadiAnt DICOM Viewer ≤ 2025.2 (all platforms).
Why It Matters for Compliance & Audit Readiness
- Patch management is a core SOC 2 CC6.1 control; undocumented or delayed updates constitute a control gap that auditors will flag.
- Demonstrating that only trusted DICOM sources are processed satisfies the “System Operations” criteria for change and access controls.
- Continuous evidence of remediation (patch version, mitigation status) feeds directly into a Trust Center audit trail, reducing “under‑investigation” findings during SOC 2 examinations.
Recommended Actions
- Upgrade all RadiAnt installations to version 2026.1 immediately.
- Enforce a policy to open DICOM files only from verified, trusted sources.
- Capture patch‑install logs and mitigation settings (CFG, DEP, ASLR) as SOC 2 evidence.
- Map the vulnerability to the relevant SOC 2 control (CC6.1 – System Operations) and record remediation in your continuous‑compliance platform.
Source: CISA Advisory ICS‑MA‑26‑218‑01