Exploitation Summary
EIP tracks 2 public exploits for CVE-2019-11687. PoCs published by kosmokato, kosmokat.
AI-analyzed exploit summary This repository contains a polyglot DICOM/PE file (PEDICOM) that exploits CVE-2019-11687, allowing execution as both a legitimate DICOM file and a malicious PE. The exploit leverages the vulnerability in DICOM file parsing to achieve remote code execution (RCE).
Description
An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The 128-byte preamble of a DICOM file that complies with this specification can contain arbitrary executable headers for multiple operating systems, including Portable Executable (PE) files for Windows and Executable and Linkable Format (ELF) files for Linux-based systems. This space is left unspecified so that dual-purpose files can be created. For example, dual-purpose TIFF/DICOM files are used in digital whole slide imaging applications in medicine. This design flaw enables system-wide compromise as malicious DICOM files are routinely shared between medical devices and hospital systems and transported via removable media for patient care coordination. To exploit this vulnerability, someone must execute the maliciously crafted file. These files can be executable even with the .dcm file extension. Anti-malware configurations at healthcare facilities often ignore medical imagery. DICOM files exist on systems that process protected health information, and successful exploitation could result in violations of regulatory compliance requirements such as HIPAA and FDA postmarket obligations.
Exploits (2)
This repository contains a polyglot DICOM/PE file (PEDICOM) that exploits CVE-2019-11687, allowing execution as both a legitimate DICOM file and a malicious PE. The exploit leverages the vulnerability in DICOM file parsing to achieve remote code execution (RCE).
This repository contains a polyglot file (DoomDicom.dcm) that exploits CVE-2019-11687 by acting as both a functional PE and a legitimate DICOM file. The exploit leverages the vulnerability in MicroDicomViewer to achieve remote code execution when the file is opened.
References (5)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H