CVE-2024-23914: Merative Merge Dicom Toolkit C/c++

Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception.

Affected products

  • Merative Merge Dicom Toolkit C/c++: from v5.6.0, up to and including v5.17.0
  • Merative Merge Dicom Toolkit C C\+\+: from 5.6.0, up to and including 5.17.0

Published 2024-05-03. Last modified 2026-06-17.