CVE-2018-25320: ACL Analytics RCE Risk
TL;DR - CVE-2018-25320 is a CVSS 9.8 arbitrary code execution vulnerability in ACL Analytics 11.x through 13.0.0.579. - Public exploit material is referenced, but active exploitation is not confirmed and the CVE is not listed in CISA KEV. - Inventory affected systems, restrict exposure, investigate
EXECUTE,bitsadmin, and PowerShell activity, and obtain a vendor-supported fix.
Summary
CVE-2018-25320 affects ACL Analytics versions 11.x through 13.0.0.579. The NVD description attributes the vulnerability to the product’s EXECUTE function, which can allow attackers to invoke arbitrary operating-system commands. The described attack chain includes downloading malicious PowerShell scripts with bitsadmin, executing those scripts with system privileges, and establishing a reverse shell.
| Field | Assessment |
|---|---|
| CVE ID | CVE-2018-25320 |
| CVSS v3 base score | 9.8, Critical |
| CVSS vector | Not included in the retrieved NVD record; do not infer it |
| Attack vector | Not independently verified from the available record |
| Authentication required | Unknown from the available record |
| Privileges required | Unknown from the available record; the resulting command execution is described as system-level |
| Affected product | ACL Analytics |
| Affected versions | 11.x through 13.0.0.579 |
| Patch available | No specific fixed version was identified |
| CISA KEV status | Not listed |
The 9.8 score indicates a critical assessment, but the missing vector prevents defenders from validating individual CVSS components such as network reachability, attack complexity, privileges required, and user interaction. Operational teams should not fill those gaps by assuming the vulnerability is remotely exploitable without authentication. Use the product’s deployment model and local telemetry to determine how attackers could reach the affected functionality.
The supplied research identifies Exploit-DB entry 44281 as public exploit material associated with the vulnerability. That raises the likelihood of opportunistic targeting, particularly where ACL Analytics systems process untrusted files or are accessible to users or services outside the organization’s trusted administrative boundary.
Analyst’s Take: Treat this as an urgent exposure-management problem, not as confirmed active exploitation. The critical score and public exploit reference justify rapid inventory and containment, while the missing CVSS vector and absence from CISA KEV limit what can be concluded about reachability and exploitation at scale.
Root Cause
The documented root cause is insufficiently constrained command execution through ACL Analytics’ EXECUTE function. Rather than limiting execution to a safe allowlist or preventing attacker-controlled command content, the vulnerable functionality can move input from the product into operating-system command execution.
The NVD description identifies a Windows-oriented post-exploitation chain. An attacker may use bitsadmin to download a malicious PowerShell script, execute the script, and create a reverse shell. If the ACL Analytics process or its execution context has system-level privileges, exploitation can lead to full host compromise rather than only data exposure within the analytics application.
Technical Notes
Investigate process lineage from ACL Analytics to a command interpreter or Windows utility. Product executable names and installation paths can vary, so defenders should first identify the locally installed executable and then search for child processes such as cmd.exe, powershell.exe, pwsh.exe, and bitsadmin.exe.
A representative Windows process-creation query using Microsoft Defender XDR Advanced Hunting is:
DeviceProcessEvents
| where Timestamp > ago(30d)
| where FileName =~ "bitsadmin.exe"
or FileName =~ "powershell.exe"
or FileName =~ "pwsh.exe"
or FileName =~ "cmd.exe"
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName,
InitiatingProcessCommandLine, FileName, ProcessCommandLine
| order by Timestamp desc
This query is a starting point, not proof of exploitation. Legitimate administrative activity can use these binaries. Suspicion increases when the initiating process is ACL Analytics, when bitsadmin uses transfer or job-management arguments, or when PowerShell makes an outbound connection shortly after an analytics file is opened or processed.
Who’s Exposed
The authoritative affected range available in the retrieved NVD record is ACL Analytics 11.x through 13.0.0.579. This includes ACL Analytics 11.x, ACL Analytics 12.x, and ACL Analytics 13.0.0 through 13.0.0.579. Organizations should treat every installation in that range as affected until ACL provides a supported corrective release or migration instruction.
The available records do not establish a fixed version. Defenders should not assume that ACL Analytics 14.x, a later 13.x build, or another release is safe merely because its version number is higher. Confirm the fixed build directly with ACL or through a vendor-supported update channel before marking an installation remediated.
Technical Notes
A practical inventory should combine software inventory, endpoint telemetry, and filesystem checks. The following PowerShell example searches common uninstall registry locations for ACL-related entries; it is an inventory aid, not a definitive product-detection method:
$paths = @(
'HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
Get-ItemProperty $paths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -match '(?i)ACL Analytics' } |
Select-Object DisplayName, DisplayVersion, Publisher, InstallDate, PSPath
Record the exact product name and build reported by each host. Include offline systems, virtual desktops, application servers, analyst workstations, and systems that process analytics files automatically. Exposure is especially important where the application runs with elevated privileges or can access sensitive financial, audit, identity, or operational data.
Severity Breakdown
CVE-2018-25320 has a reported CVSS v3 base score of 9.8, classified as Critical. The impact described by the vulnerability record is consistent with a high-consequence code execution issue: an attacker may run commands, download additional payloads, establish a reverse shell, and potentially obtain complete control of the host.
The exact CVSS vector was not included in the retrieved NVD response. Consequently, the individual components cannot be verified. Attack vector, attack complexity, privileges required, user interaction, scope, confidentiality impact, integrity impact, and availability impact should all be treated as unavailable rather than inferred from the 9.8 score.
| CVSS element | Available conclusion |
|---|---|
| Base score | 9.8 |
| Severity | Critical |
| Vector string | Not available in the retrieved record |
| Attack vector | Unknown |
| Attack complexity | Unknown |
| Privileges required | Unknown |
| User interaction | Unknown |
| Scope | Unknown |
| Confidentiality, integrity, availability impact | The described outcome is potentially complete host compromise, but component values are not verified |
For prioritization, the combination of critical severity, public exploit material, and possible system-level execution warrants urgent handling. CISA KEV status and the available exploitation evidence do not support describing this vulnerability as confirmed active exploitation.
Exploitation Status
A public exploit reference exists: Exploit-DB entry 44281 is associated with CVE-2018-25320. Public availability means defenders should assume that capable attackers can study or adapt the technique; it does not establish that the exploit works against every affected installation or that exploitation is occurring at scale.
Active exploitation in the wild is not confirmed by the supplied evidence. CVE-2018-25320 is not listed in the CISA Known Exploited Vulnerabilities catalog, and no verified exploitation campaign or ransomware association was established in the retrieved sources. The NVD description’s reference to reverse shells, bitsadmin, and PowerShell describes a possible attack chain, not observed campaign telemetry.
The social and GitHub mention counts in this article’s metadata are set to zero because no independently verified counts were supplied; they should not be interpreted as proof that no mentions exist. Likewise, no EPSS percentile was provided. Organizations should use their own threat-intelligence sources and current EPSS data if those metrics are required for queue prioritization.
Sources
The primary technical reference is the NVD record for CVE-2018-25320:
The public exploit reference identified in the research note is:
Vendor and product references include:
Additional advisory and exploitation-status references are:
- VulnCheck advisory: ACL Analytics 11.x arbitrary code execution
- CISA Known Exploited Vulnerabilities Catalog
These sources establish the affected range, severity, public exploit reference, and current non-KEV status described above. They do not establish a fixed version or confirm active exploitation in the wild. Until ACL publishes a verifiable remediation target, organizations should first inventory ACL Analytics 11.x through 13.0.0.579, restrict exposure, and apply compensating controls.
This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.
Detection Guidance
Detection should focus on the transition from ACL Analytics activity to operating-system command execution. Review process creation, PowerShell script-block logging, Windows Filtering Platform or proxy telemetry, and endpoint alerts for bitsadmin, especially when the initiating process is ACL Analytics or an unusual user-session process.
Organizations should retain relevant endpoint, authentication, DNS, proxy, and process telemetry long enough to support retrospective investigation. See the log retention glossary for background on retention planning and investigation requirements.
On affected systems, also search for reverse-shell indicators, unexpected outbound connections, newly created scheduled tasks or services, startup persistence, local-account changes, and credential access. If the application runs as a service account or local system, investigate all activity under that identity rather than limiting review to interactive user sessions.
Technical Notes
For Microsoft Defender XDR, the following query looks for suspicious command utilities launched by a process associated with ACL Analytics. Adjust the executable-name condition after confirming the product’s local binary name:
DeviceProcessEvents
| where Timestamp > ago(30d)
| where InitiatingProcessFileName has_any ("ACL", "ACLAnalytics")
| where FileName in~ ("bitsadmin.exe", "powershell.exe", "pwsh.exe",
"cmd.exe", "cscript.exe", "wscript.exe")
| project Timestamp, DeviceName, AccountName,
InitiatingProcessFileName, InitiatingProcessCommandLine,
FileName, ProcessCommandLine, SHA256
A second query can identify PowerShell activity containing download or reverse-shell terms. These terms are noisy and require validation:
DeviceProcessEvents
| where Timestamp > ago(30d)
| where FileName in~ ("powershell.exe", "pwsh.exe")
| where ProcessCommandLine matches regex @"(?i)(bitsadmin|Invoke-WebRequest|WebClient|DownloadString|DownloadFile|FromBase64String|reverse|socket)"
| project Timestamp, DeviceName, AccountName,
InitiatingProcessFileName, ProcessCommandLine
Preserve process trees, command lines, PowerShell 4103 and 4104 events where enabled, Security 4688 events, DNS records, proxy logs, and outbound connection data. If logging was not enabled before the suspected event, collect the endpoint image and available EDR timeline rather than relying only on current process state.
Remediation Steps
No specific fixed version was identified in the retrieved NVD record or the reviewed ACL pages. Obtain a vendor-supported update or migration path directly from ACL, verify the exact fixed build, and upgrade every installation in the affected range. Do not record an installation as remediated solely because it moved beyond version 13.0.0.579 unless ACL confirms that version as fixed.
Until a supported fix is confirmed, restrict access to affected hosts, prevent untrusted users or files from reaching ACL Analytics, remove unnecessary administrative privileges, and monitor or block suspicious child-process execution. If business operations permit it, temporarily disable or remove workflows that invoke the EXECUTE function. Do not disable the function blindly where it is required for critical processing without testing the operational impact.
Organizations reviewing their endpoint protection coverage may also compare their existing EDR and application-control capabilities with products such as Get Bitdefender →. Any security product should be evaluated against the organization’s logging, isolation, application-control, and incident-response requirements rather than selected solely on brand recognition.
Security teams can also map these controls to the organization’s broader security baseline and prioritize relevant safeguards using the CIS Critical Security Controls list.
Technical Notes
After obtaining the official vendor package and confirming its fixed version, a Windows Installer deployment can use a command of this form:
msiexec.exe /i .\ACL-Analytics-<vendor-approved-fixed-version>.msi /qn /norestart
The placeholder must be replaced with the actual ACL-supplied installer and confirmed fixed version. The available evidence does not provide a legitimate package name or fixed release, so administrators should not download or substitute an unverified installer.
A concrete interim control is to use application control to block bitsadmin.exe for the affected application context, provided the organization has validated that no approved workflows depend on it. With AppLocker, create a publisher, path, or hash rule that denies bitsadmin.exe to the relevant user or service identities. With Microsoft Defender, administrators can also audit PowerShell and child-process behavior before enforcing a block. These controls reduce the documented download-and-execute chain but do not correct the underlying EXECUTE vulnerability.
If compromise is suspected, isolate the host from the network, preserve forensic data, terminate unauthorized persistence only after evidence capture, rotate credentials used on the system, and review lateral movement from the host. Rebuild or restore from a trusted source when system-level compromise cannot be ruled out.