Security News

DICOM Standard Flaw Could Compromise Medical Device Security

A flaw in the DICOM digital image standard could compromise medical device security and be used by attackers to embed malware in medical images.

medical image

Source: Thinkstock

By Fred Donovan

- A flaw in the Digital Imaging and Communications in Medicine (DICOM) standard could compromise medical device security and be used by attackers to embed malware in medical images, warned Markel Picado Ortiz, a security researcher with Cylera Labs.

DICOM is a data standard for handling, storing, printing, and transmitting information in medical imaging, including a file format definition and a network communications protocol.

The researcher explained that the DICOM file can be converted into a portable executable (PE) file. When the conversion takes place, the file can then be used by an attacker to infect a hospital’s IT infrastructure with malware. It could also be used to upload bogus images to the hospital’s picture archiving and communication system (PACS).