Skip to content
eastbaycyber

CVE-2018-25320: ACL Analytics RCE Risk

CVSS · Critical
9.8
In CISA KEV
No
Published
Oct 3
CVE explainers 10 min read
Security Research Desk Source-checked
Auto-checked against the official CVE record · Human-reviewed after publishing · Updated 2026-10-03
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

TL;DR - CVE-2018-25320 is a CVSS 9.8 arbitrary code execution vulnerability in ACL Analytics 11.x through 13.0.0.579. - Public exploit material is referenced, but active exploitation is not confirmed and the CVE is not listed in CISA KEV. - Inventory affected systems, restrict exposure, investigate EXECUTE, bitsadmin, and PowerShell activity, and obtain a vendor-supported fix.

Summary

CVE-2018-25320 affects ACL Analytics versions 11.x through 13.0.0.579. The NVD description attributes the vulnerability to the product’s EXECUTE function, which can allow attackers to invoke arbitrary operating-system commands. The described attack chain includes downloading malicious PowerShell scripts with bitsadmin, executing those scripts with system privileges, and establishing a reverse shell.

Field Assessment
CVE ID CVE-2018-25320
CVSS v3 base score 9.8, Critical
CVSS vector Not included in the retrieved NVD record; do not infer it
Attack vector Not independently verified from the available record
Authentication required Unknown from the available record
Privileges required Unknown from the available record; the resulting command execution is described as system-level
Affected product ACL Analytics
Affected versions 11.x through 13.0.0.579
Patch available No specific fixed version was identified
CISA KEV status Not listed

The 9.8 score indicates a critical assessment, but the missing vector prevents defenders from validating individual CVSS components such as network reachability, attack complexity, privileges required, and user interaction. Operational teams should not fill those gaps by assuming the vulnerability is remotely exploitable without authentication. Use the product’s deployment model and local telemetry to determine how attackers could reach the affected functionality.

The supplied research identifies Exploit-DB entry 44281 as public exploit material associated with the vulnerability. That raises the likelihood of opportunistic targeting, particularly where ACL Analytics systems process untrusted files or are accessible to users or services outside the organization’s trusted administrative boundary.

Analyst’s Take: Treat this as an urgent exposure-management problem, not as confirmed active exploitation. The critical score and public exploit reference justify rapid inventory and containment, while the missing CVSS vector and absence from CISA KEV limit what can be concluded about reachability and exploitation at scale.

AnalystImpact · assess the risk

Root Cause

The documented root cause is insufficiently constrained command execution through ACL Analytics’ EXECUTE function. Rather than limiting execution to a safe allowlist or preventing attacker-controlled command content, the vulnerable functionality can move input from the product into operating-system command execution.

The NVD description identifies a Windows-oriented post-exploitation chain. An attacker may use bitsadmin to download a malicious PowerShell script, execute the script, and create a reverse shell. If the ACL Analytics process or its execution context has system-level privileges, exploitation can lead to full host compromise rather than only data exposure within the analytics application.

Technical Notes

Investigate process lineage from ACL Analytics to a command interpreter or Windows utility. Product executable names and installation paths can vary, so defenders should first identify the locally installed executable and then search for child processes such as cmd.exe, powershell.exe, pwsh.exe, and bitsadmin.exe.

A representative Windows process-creation query using Microsoft Defender XDR Advanced Hunting is:

DeviceProcessEvents
| where Timestamp > ago(30d)
| where FileName =~ "bitsadmin.exe"
    or FileName =~ "powershell.exe"
    or FileName =~ "pwsh.exe"
    or FileName =~ "cmd.exe"
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName,
          InitiatingProcessCommandLine, FileName, ProcessCommandLine
| order by Timestamp desc

This query is a starting point, not proof of exploitation. Legitimate administrative activity can use these binaries. Suspicion increases when the initiating process is ACL Analytics, when bitsadmin uses transfer or job-management arguments, or when PowerShell makes an outbound connection shortly after an analytics file is opened or processed.

Who’s Exposed

The authoritative affected range available in the retrieved NVD record is ACL Analytics 11.x through 13.0.0.579. This includes ACL Analytics 11.x, ACL Analytics 12.x, and ACL Analytics 13.0.0 through 13.0.0.579. Organizations should treat every installation in that range as affected until ACL provides a supported corrective release or migration instruction.

The available records do not establish a fixed version. Defenders should not assume that ACL Analytics 14.x, a later 13.x build, or another release is safe merely because its version number is higher. Confirm the fixed build directly with ACL or through a vendor-supported update channel before marking an installation remediated.

Technical Notes

A practical inventory should combine software inventory, endpoint telemetry, and filesystem checks. The following PowerShell example searches common uninstall registry locations for ACL-related entries; it is an inventory aid, not a definitive product-detection method:

$paths = @(
  'HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*',
  'HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)

Get-ItemProperty $paths -ErrorAction SilentlyContinue |
  Where-Object { $_.DisplayName -match '(?i)ACL Analytics' } |
  Select-Object DisplayName, DisplayVersion, Publisher, InstallDate, PSPath

Record the exact product name and build reported by each host. Include offline systems, virtual desktops, application servers, analyst workstations, and systems that process analytics files automatically. Exposure is especially important where the application runs with elevated privileges or can access sensitive financial, audit, identity, or operational data.

Severity Breakdown

CVE-2018-25320 has a reported CVSS v3 base score of 9.8, classified as Critical. The impact described by the vulnerability record is consistent with a high-consequence code execution issue: an attacker may run commands, download additional payloads, establish a reverse shell, and potentially obtain complete control of the host.

The exact CVSS vector was not included in the retrieved NVD response. Consequently, the individual components cannot be verified. Attack vector, attack complexity, privileges required, user interaction, scope, confidentiality impact, integrity impact, and availability impact should all be treated as unavailable rather than inferred from the 9.8 score.

CVSS element Available conclusion
Base score 9.8
Severity Critical
Vector string Not available in the retrieved record
Attack vector Unknown
Attack complexity Unknown
Privileges required Unknown
User interaction Unknown
Scope Unknown
Confidentiality, integrity, availability impact The described outcome is potentially complete host compromise, but component values are not verified

For prioritization, the combination of critical severity, public exploit material, and possible system-level execution warrants urgent handling. CISA KEV status and the available exploitation evidence do not support describing this vulnerability as confirmed active exploitation.

Exploitation Status

A public exploit reference exists: Exploit-DB entry 44281 is associated with CVE-2018-25320. Public availability means defenders should assume that capable attackers can study or adapt the technique; it does not establish that the exploit works against every affected installation or that exploitation is occurring at scale.

Active exploitation in the wild is not confirmed by the supplied evidence. CVE-2018-25320 is not listed in the CISA Known Exploited Vulnerabilities catalog, and no verified exploitation campaign or ransomware association was established in the retrieved sources. The NVD description’s reference to reverse shells, bitsadmin, and PowerShell describes a possible attack chain, not observed campaign telemetry.

The social and GitHub mention counts in this article’s metadata are set to zero because no independently verified counts were supplied; they should not be interpreted as proof that no mentions exist. Likewise, no EPSS percentile was provided. Organizations should use their own threat-intelligence sources and current EPSS data if those metrics are required for queue prioritization.

Sources

The primary technical reference is the NVD record for CVE-2018-25320:

The public exploit reference identified in the research note is:

Vendor and product references include:

Additional advisory and exploitation-status references are:

These sources establish the affected range, severity, public exploit reference, and current non-KEV status described above. They do not establish a fixed version or confirm active exploitation in the wild. Until ACL publishes a verifiable remediation target, organizations should first inventory ACL Analytics 11.x through 13.0.0.579, restrict exposure, and apply compensating controls.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

ResponderRunbook · act now

Detection Guidance

Detection should focus on the transition from ACL Analytics activity to operating-system command execution. Review process creation, PowerShell script-block logging, Windows Filtering Platform or proxy telemetry, and endpoint alerts for bitsadmin, especially when the initiating process is ACL Analytics or an unusual user-session process.

Organizations should retain relevant endpoint, authentication, DNS, proxy, and process telemetry long enough to support retrospective investigation. See the log retention glossary for background on retention planning and investigation requirements.

On affected systems, also search for reverse-shell indicators, unexpected outbound connections, newly created scheduled tasks or services, startup persistence, local-account changes, and credential access. If the application runs as a service account or local system, investigate all activity under that identity rather than limiting review to interactive user sessions.

Technical Notes

For Microsoft Defender XDR, the following query looks for suspicious command utilities launched by a process associated with ACL Analytics. Adjust the executable-name condition after confirming the product’s local binary name:

DeviceProcessEvents
| where Timestamp > ago(30d)
| where InitiatingProcessFileName has_any ("ACL", "ACLAnalytics")
| where FileName in~ ("bitsadmin.exe", "powershell.exe", "pwsh.exe",
                      "cmd.exe", "cscript.exe", "wscript.exe")
| project Timestamp, DeviceName, AccountName,
          InitiatingProcessFileName, InitiatingProcessCommandLine,
          FileName, ProcessCommandLine, SHA256

A second query can identify PowerShell activity containing download or reverse-shell terms. These terms are noisy and require validation:

DeviceProcessEvents
| where Timestamp > ago(30d)
| where FileName in~ ("powershell.exe", "pwsh.exe")
| where ProcessCommandLine matches regex @"(?i)(bitsadmin|Invoke-WebRequest|WebClient|DownloadString|DownloadFile|FromBase64String|reverse|socket)"
| project Timestamp, DeviceName, AccountName,
          InitiatingProcessFileName, ProcessCommandLine

Preserve process trees, command lines, PowerShell 4103 and 4104 events where enabled, Security 4688 events, DNS records, proxy logs, and outbound connection data. If logging was not enabled before the suspected event, collect the endpoint image and available EDR timeline rather than relying only on current process state.

Remediation Steps

No specific fixed version was identified in the retrieved NVD record or the reviewed ACL pages. Obtain a vendor-supported update or migration path directly from ACL, verify the exact fixed build, and upgrade every installation in the affected range. Do not record an installation as remediated solely because it moved beyond version 13.0.0.579 unless ACL confirms that version as fixed.

Until a supported fix is confirmed, restrict access to affected hosts, prevent untrusted users or files from reaching ACL Analytics, remove unnecessary administrative privileges, and monitor or block suspicious child-process execution. If business operations permit it, temporarily disable or remove workflows that invoke the EXECUTE function. Do not disable the function blindly where it is required for critical processing without testing the operational impact.

Organizations reviewing their endpoint protection coverage may also compare their existing EDR and application-control capabilities with products such as Get Bitdefender →. Any security product should be evaluated against the organization’s logging, isolation, application-control, and incident-response requirements rather than selected solely on brand recognition.

Security teams can also map these controls to the organization’s broader security baseline and prioritize relevant safeguards using the CIS Critical Security Controls list.

Technical Notes

After obtaining the official vendor package and confirming its fixed version, a Windows Installer deployment can use a command of this form:

msiexec.exe /i .\ACL-Analytics-<vendor-approved-fixed-version>.msi /qn /norestart

The placeholder must be replaced with the actual ACL-supplied installer and confirmed fixed version. The available evidence does not provide a legitimate package name or fixed release, so administrators should not download or substitute an unverified installer.

A concrete interim control is to use application control to block bitsadmin.exe for the affected application context, provided the organization has validated that no approved workflows depend on it. With AppLocker, create a publisher, path, or hash rule that denies bitsadmin.exe to the relevant user or service identities. With Microsoft Defender, administrators can also audit PowerShell and child-process behavior before enforcing a block. These controls reduce the documented download-and-execute chain but do not correct the underlying EXECUTE vulnerability.

If compromise is suspected, isolate the host from the network, preserve forensic data, terminate unauthorized persistence only after evidence capture, rotate credentials used on the system, and review lateral movement from the host. Rebuild or restore from a trusted source when system-level compromise cannot be ruled out.

Last verified: 2026-10-03

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.