---
id: CVE-2018-25320
title: ACL Analytics 11.x - 13.0.0.579 Arbitrary Code Execution
summary: >-
  ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code
  execution vulnerability that allows attackers to execute arbitrary commands by
  leveraging the EXECUTE function. Attackers can use bitsadmin to download
  malicious Po…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-94
vendor: acl
product: ACL Analytics
affected:
  - analytics >= 11.0 <= 13.0.0.579
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-05-18T17:59:13.076112Z'
exploitAvailable: true
published: '2026-05-17'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:15.190Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2018-25320'
references:
  - url: 'https://www.exploit-db.com/exploits/44281'
    label: ExploitDB-44281
  - url: 'https://www.acl.com'
    label: Official Product Homepage
  - url: 'https://www.acl.com/products/acl-analytics/'
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/acl-analytics-11-x-arbitrary-code-execution
    label: >-
      VulnCheck Advisory: ACL Analytics 11.x - 13.0.0.579 Arbitrary Code
      Execution
tags:
  - cve.org
  - exploit-available
epss: 0.00576
epssPercentile: 0.45454
ingestedAt: '2026-10-01T15:48:17.886Z'
---

## Overview

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control.

## Affected

- `analytics >= 11.0 <= 13.0.0.579`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
