Arbitrary EXE Execution Vulnerability in Qlik Sense Enterprise for Windows
CVE-2024-55579

8.8HIGH

Key Information:

Vendor
CVE Published:
9 December 2024

What is CVE-2024-55579?

An unprivileged user with network access may exploit a vulnerability in Qlik Sense Enterprise for Windows, enabling the creation of connection objects that trigger the execution of arbitrary executable files. This poses a significant risk as it allows unauthorized execution of potentially harmful applications. The issue has been addressed in various patches and updates, ensuring enhanced security for users of Qlik Sense Enterprise. It is crucial for organizations to apply the necessary updates to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.