Executive brief
HCL BigFix Service Management (SM) is susceptible to a vulnerability where it fails to properly clean data before it is exported into spreadsheet files like Excel or CSVs. An attacker could input malicious formulas into the system that, when exported and opened by a legitimate user, could lead to unauthorized data being sent to the attacker or other malicious actions on the user's computer. While modern spreadsheet software often warns users about this type of content, the flaw could still be used to target employees who handle exported reports.
Technical details
A CSV Injection (also known as Formula Injection) vulnerability exists in HCL BigFix Service Management (SM) version 23.0. The application fails to properly sanitize user-supplied input before including it in exported spreadsheet files (CSV, XLS, XLSX). An authenticated attacker can populate data fields with malicious spreadsheet formulas (e.g., starting with =, +, -, or @). When a victim exports this data and opens the resulting file in a spreadsheet application like Microsoft Excel, the formulas may execute, potentially leading to information exfiltration via DDE or other malicious activities. Exploitation requires the attacker to have sufficient privileges to input data and relies on user interaction to open the exported file.
Affected products
- HCL Software BigFix Service Management (SM) 23.0
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory: Vendor advisory KB0128144 published