vendor:
ACL Analytics
by:
Clutchisback1
7.5
CVSS
HIGH
Code Execution
78
CWE
Product Name: ACL Analytics
Affected Version From: 11.x
Affected Version To: 13.0.0.579
Patch Exists: YES
Related CWE: N/A
CPE: a:acl:acl_analytics
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 pro SP1 x86
2018
Arbitrary Code Execution
This exploit allows an attacker to execute arbitrary code on the target host by downloading a reverse shell payload from the attacker's machine and uploading it to the target host by bitsadmin and placing it in the target c:emp directory and saving it as shell.ps1. The second `Execute` command will execute the stored payload.
Mitigation:
Ensure that the system is up to date with the latest security patches and that all unnecessary services are disabled.