Junglewise Threat Intelligence

CVE-2025-50572: Archer IRM CSV injection in data export

CVE-2025-50572 · Severity: high · CVSS 8.8 · Published 2025-07-31

Executive brief

Archer IRM, a platform used by organizations to manage governance, risk, and compliance, is susceptible to a vulnerability where malicious data entered into the system can be turned into executable commands. If an attacker submits a specially crafted text entry (such as a device name) and a legitimate user later exports that data into a CSV spreadsheet, opening that file in applications like Microsoft Excel could trigger the execution of unauthorized commands on the user's computer. This could lead to a full compromise of the user's workstation and the data stored on it.

Technical details

A CSV injection (CWE-1236) vulnerability exists in Archer RSA v6.11.00204.10014 due to improper neutralization of formula elements during CSV export. An attacker can inject malicious spreadsheet formulas (e.g., starting with '=', '+', '-', or '@') into system fields such as the Device Registration form. When an administrative or authorized user exports this data to a CSV file and opens it in a compatible spreadsheet application like Microsoft Excel, the formula is executed, potentially leading to Remote Code Execution (RCE) via Dynamic Data Exchange (DDE) or similar mechanisms. The vendor has reportedly disputed the validity of this report as a product vulnerability, often citing that such issues are inherent to how spreadsheet software handles CSV data.

Affected products

  • Archer Technologies Archer IRM (formerly RSA Archer) 6.11.00204.10014

Timeline

  • 2025-07-31: advisory: Initial NVD publication
  • 2026-01-12: other: CVE record marked as disputed by the supplier

References