Impact
Velociraptor fails to sanitize cells that begin with certain characters when exporting CSV files. When a victim opens such a CSV in Microsoft Excel, Excel interprets those cells as formulas and executes them, allowing an attacker to run arbitrary code. The weakness is a formula injection flaw documented as CWE‑1236, and it can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Rapid7 Velociraptor, a monitoring and forensic tool. No specific product versions are listed in the advisory, so any release that exports CSV data via the GUI, offline collector, or data export mechanisms is potentially impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity vulnerability, and the EPSS score is currently unavailable, suggesting that the exploit probability is not quantified. The issue is not listed in the CISA KEV catalog, but because it relies on the common behavior of Excel, attackers could target users who regularly open exported CSV reports. The likely attack vector is a social‑engineering scenario where an attacker sends a malicious CSV file to an end‑user who opens it in Excel or Google Docs.
OpenCVE Enrichment