CVE-2018-25320 is a critical (CVSS 3.1 base 9.8) arbitrary code execution vulnerability in ACL Analytics versions 11.x through 13.0.0.579. Despite the 2018 CVE identifier, NVD’s own scoring for this record dates to 2026 — a backlog-clearing pattern where NVD assigns modern CVSS scoring to an older, previously-unscored disclosure rather than this being a newly discovered flaw.
What the vulnerability does
Per NVD’s description, ACL Analytics’ EXECUTE function allows attackers to run arbitrary commands. A public exploit (referenced via Exploit-DB) demonstrates using bitsadmin — a legitimate Windows utility for background file transfers — to download a malicious PowerShell script and execute it with system privileges, establishing a reverse shell and full system control.
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw needing no authentication or user interaction, with full confidentiality, integrity, and availability impact — consistent with the documented outcome of complete system compromise.
Why this is only surfacing now
A 2018-dated CVE ID with 2026 NVD scoring reflects NVD’s ongoing effort to work through a backlog of vulnerabilities that were assigned an ID and publicly disclosed (in this case, via Exploit-DB and VulnCheck’s own advisory) years ago but never received formal NVD analysis and a CVSS score until now. This is a real, if unusual, category worth naming explicitly: the vulnerability itself isn’t new, but its presence in NVD’s authoritative scoring data is.
What we don’t yet have
This record traces to NVD’s description and reference set (vendor site, Exploit-DB, VulnCheck); no CISA KEV listing is present, and we don’t have confirmation of whether ACL Analytics (a data-analytics product, now under the Galvanize/Diligent product family per its vendor references) has shipped a fix for the affected 11.x–13.0.0.579 range. Confidence is medium.
Why this matters
Given the vulnerability’s age (originally disclosed circa 2018) and the existence of public exploit code since that time, any organization still running an affected ACL Analytics version has had this exposure for years, likely without it appearing in vulnerability scanning tied to NVD’s CVSS data until this recent scoring. Organizations using ACL Analytics should confirm their deployed version against the 11.x–13.0.0.579 range regardless of this CVE’s age.
Frequently Asked Questions
What is CVE-2018-25320? A CVSS 9.8 critical arbitrary code execution vulnerability in ACL Analytics versions 11.x through 13.0.0.579, exploitable via the product’s EXECUTE function.
Why does a 2018 CVE have a 2026 publish date in this article? NVD only recently assigned a CVSS score and formal analysis to this pre-existing, publicly disclosed vulnerability — the flaw itself is not new.
Is CVE-2018-25320 being actively exploited? Public exploit code has existed since the original disclosure, but it is not listed in CISA’s Known Exploited Vulnerabilities catalog as of this writing.
Data sourced from the National Vulnerability Database (NVD), aggregated September 2026. See more vulnerability intelligence.