PT-2026-41546 · Galvanize · Acl Analytics

Published

2026-05-17

·

Updated

2026-05-17

·

CVE-2018-25320

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ACL Analytics versions 11.x through 13.0.0.579
Description An issue allows attackers to execute arbitrary commands by leveraging the EXECUTE() function. This can be exploited using bitsadmin to download and run malicious PowerShell scripts with system privileges, enabling the establishment of reverse shells and full system control.
Recommendations As a temporary workaround, consider restricting the use of the EXECUTE() function to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2018-25320

Affected Products

Acl Analytics