Arbitrary Code Execution Vulnerability in ACL Analytics by ACL Services
CVE-2018-25320
Key Information:
- Vendor
Acl
- Status
- Vendor
- CVE Published:
- 17 May 2026
Badges
What is CVE-2018-25320?
ACL Analytics versions 11.x through 13.0.0.579 are susceptible to an arbitrary code execution vulnerability that enables attackers to run arbitrary commands. By exploiting the EXECUTE function, attackers can utilize bitsadmin to download and execute malicious PowerShell scripts with system privileges. This capability allows for the establishment of reverse shells, giving attackers full system control and posing a significant threat to the integrity and confidentiality of the affected systems.
Affected Version(s)
ACL Analytics 11.x - 13.0.0.579
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
