Executive brief
Iron Mountain enVision, a platform used for digital archiving and document management, contains a critical security flaw that allows unauthorized individuals to execute commands on the underlying server. An attacker could exploit this to gain full control over the system, potentially leading to the theft of sensitive archived data, service disruption, or the use of the server for further attacks. This vulnerability can be exploited remotely over the network without any user interaction or login credentials.
Technical details
An OS command injection vulnerability (CWE-78) exists in Iron Mountain Archiving Services enVision due to improper neutralization of special elements used in OS commands. The flaw allows a remote, unauthenticated attacker to send specially crafted requests over the network to execute arbitrary code with the privileges of the application. The vulnerability is rated with a CVSS score of 10.0 as it requires no authentication, has low attack complexity, and can result in a complete compromise of confidentiality, integrity, and availability. Users are advised to update to version 250563 or later to remediate the issue.
Affected products
- Iron Mountain Archiving Services enVision before 250563
Timeline
- 2025-09-23: advisory: Initial publication of CVE-2025-9588