InVesalius versions 3.1.99991 through 3.1.99998 contain an eval injection flaw in the DICOM parsing/reading logic located in invesalius/reader/dicom.py. When the application loads a specially crafted DICOM file, attacker-controlled content is evaluated via unsafe use of eval, enabling execution of arbitrary code in the context of the InVesalius process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2024-42845, a Remote Code Execution (RCE) vulnerability in Invesalius3 (versions 3.1.99991 to 3.1.99998) on Windows. The exploit consists of a Python script (CVE-2024-42845.py) that takes a valid DICOM file and injects a base64-encoded, arbitrary Python payload into the DICOM tag 0x0020,0x0032. The script allows the user to specify the input DICOM file, the output file, and the payload (as a file containing Python code). When the crafted DICOM file is imported into a vulnerable version of Invesalius3, the payload is executed, resulting in code execution on the victim's machine. The README.md provides detailed background, usage instructions, and references. The exploit is operational and allows for arbitrary code execution, but does not provide a reverse shell or similar weaponized payload by default. The main attack vector is local, requiring the victim to import the malicious DICOM file.
This repository contains proof-of-concept exploits for two vulnerabilities in Invesalius3, an open-source medical imaging application. The structure is organized by CVE, with each vulnerability having its own folder containing a README and exploit code. For CVE-2024-42845, the exploit targets a remote code execution vulnerability in the DICOM file import process. The exploit script (exploit.py) crafts a malicious DICOM file by injecting a Python payload into the (0x0020, 0x0032) tag, exploiting the use of eval in the vulnerable function. Example payloads include reverse shells (provided in res/rev_1.py and res/rev_2.py), which connect back to 127.0.0.1:4444. The exploit is triggered when a victim imports the crafted DICOM file into a vulnerable Invesalius3 client. For CVE-2024-44825, the exploit targets a directory traversal vulnerability in the .inv3 (tar) file import process. The exploit script (exploit.py) modifies a sample project, then creates a tar archive with file paths crafted to traverse directories (using '..\..\[CHANGEME]\'). When imported, this allows arbitrary files to be written to the victim's filesystem. The README provides detailed instructions and context for both vulnerabilities. Overall, the repository is well-structured, with clear separation of exploits, payloads, and documentation. The exploits are proof-of-concept and require user interaction (importing a crafted file) to trigger the vulnerabilities.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.