nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25320 CVE-2018-25320
CRITICAL
ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Execution
Record summary
CVE-2018-25320 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ACL AnalyticsBrowse acl / ACL Analytics | CVE List | 11.0 to ≤ 13.0.0.579 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBACL Analytics 11.X - 13.0.0.579 - Arbitrary Code ExecutionExploitDB exploitby Clutchisback1Not analyzed1 file
References
5Official Product Homepageproduct
https://www.acl.com/ Product Referenceproduct
https://www.acl.com/products/acl-analytics ExploitDB-44281exploit
https://www.exploit-db.com/exploits/44281 VulnCheck Advisory: ACL Analytics 11.x - 13.0.0.579 Arbitrary Code ExecutionThird-party advisory
https://www.vulncheck.com/advisories/acl-analytics-11-x-arbitrary-code-execution