Privilege Escalation Vulnerability in Qlik Sense Enterprise for Windows
CVE-2024-36077

8.8HIGH

Key Information:

Vendor

Qlik

Vendor
CVE Published:
22 May 2024

What is CVE-2024-36077?

A privilege escalation vulnerability exists in Qlik Sense Enterprise for Windows that permits a remote attacker to gain elevated privileges. This issue stems from inadequate validation mechanisms, which can be exploited to escalate privileges to an internal system role. Once elevated, an attacker could execute arbitrary commands on the server, compromising the integrity and confidentiality of the system. The vulnerability affects several product patches released from May 2022 to February 2024, necessitating prompt remediation. This issue has been addressed in the May 2024 patch and subsequent updates.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.