Directory traversal in Centro de Tecnologia da Informacao Renato Archer InVesalius3 v3.1.99995 when processing a crafted .inv3 file, allowing an attacker to write arbitrary files to attacker-chosen paths on the underlying system (path traversal during import/extraction).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains proof-of-concept exploits for two vulnerabilities in Invesalius3, an open-source medical imaging application. The structure is organized by CVE, with each vulnerability having its own folder containing a README and exploit code. For CVE-2024-42845, the exploit targets a remote code execution vulnerability in the DICOM file import process. The exploit script (exploit.py) crafts a malicious DICOM file by injecting a Python payload into the (0x0020, 0x0032) tag, exploiting the use of eval in the vulnerable function. Example payloads include reverse shells (provided in res/rev_1.py and res/rev_2.py), which connect back to 127.0.0.1:4444. The exploit is triggered when a victim imports the crafted DICOM file into a vulnerable Invesalius3 client. For CVE-2024-44825, the exploit targets a directory traversal vulnerability in the .inv3 (tar) file import process. The exploit script (exploit.py) modifies a sample project, then creates a tar archive with file paths crafted to traverse directories (using '..\..\[CHANGEME]\'). When imported, this allows arbitrary files to be written to the victim's filesystem. The README provides detailed instructions and context for both vulnerabilities. Overall, the repository is well-structured, with clear separation of exploits, payloads, and documentation. The exploits are proof-of-concept and require user interaction (importing a crafted file) to trigger the vulnerabilities.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.