Record summary

CVE-2018-25320 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List11.0 to ≤ 13.0.0.579affected

Proofs of concept

1

Catalogued exploits

ExploitDBACL Analytics 11.X - 13.0.0.579 - Arbitrary Code ExecutionExploitDB exploitby Clutchisback1Not analyzed1 file
ExploitDB

PoC details

References

5