CVE-2025-9588

10.0

Iron Mountain Archiving Services Inc. · enVision

A critical OS command injection vulnerability exists in Iron Mountain Archiving Services Inc. enVision, allowing unauthenticated attackers to execute arbitrary system commands.

Executive summary

The enVision platform is vulnerable to critical OS command injection, which permits unauthenticated remote attackers to achieve total system compromise.

Vulnerability

This is an OS command injection vulnerability (CWE-78) occurring due to the improper neutralization of special elements in system commands. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that the vulnerability is exploitable by an unauthenticated attacker over the network without requiring user interaction.

Business impact

The ability to execute arbitrary OS commands poses an existential risk to the confidentiality, integrity, and availability of the enVision environment. Given the critical CVSS score of 10.0, this flaw allows for full system takeover, potential lateral movement into sensitive archival data stores, and complete administrative control over the affected infrastructure.

Remediation

Immediate Action: Update all instances of Iron Mountain Archiving Services Inc. enVision to version 250563 or later immediately.

Proactive Monitoring: Review system and application access logs for unusual shell-related activity or unexpected process spawning that may indicate exploitation attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict input validation rules to block malicious payloads containing shell metacharacters until the patch can be applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability cannot be overstated, as it provides a direct path to total system compromise without authentication. Organizations must prioritize the deployment of version 250563 to eliminate this risk. Failure to patch will leave the environment exposed to trivial remote exploitation.

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written
  5. Fix documented version 250563 per CVE record

Sources

Originally found and disclosed by Ceylan BOZOĞULLARINDAN, with Mehmet Emin YÜKSEL (sponsor), per the CVE Program record.