Junglewise Threat Intelligence

CVE-2018-25320: ACL ACL Analytics arbitrary code execution in EXECUTE function

CVE-2018-25320 · Severity: critical · CVSS 9.8 · Published 2026-05-17

Executive brief

ACL Analytics, a software tool used for data analysis and audit management, contains a critical security flaw. An attacker can use a built-in function to run unauthorized commands on the underlying computer system. This could allow a remote intruder to take full control of the machine, steal sensitive audit data, or disrupt business operations.

Technical details

A code injection vulnerability (CWE-94) exists in ACL Analytics versions 11.x through 13.0.0.579. The flaw resides in the 'EXECUTE' function, which fails to properly restrict command execution. A remote attacker can leverage this function to invoke system utilities like 'bitsadmin' to download malicious payloads and 'powershell' to execute them. Successful exploitation allows for arbitrary command execution with system privileges, potentially leading to a full reverse shell and complete system compromise. Public exploit code has been available since 2018.

Affected products

  • ACL ACL Analytics 11.x through 13.0.0.579

Timeline

  • 2018-03-12: disclosed: Public exploit published on Exploit-DB (EDB-44281)
  • 2026-05-17: advisory: CVE-2018-25320 published via NVD/VulnCheck

References