Critical Security Updates Released for Qlik Sense Enterprise for Windows
The vulnerabilities known as CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365 could be used together to achieve unauthenticated RCE
Summary
The vulnerabilities known as CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365 could be used together to achieve unauthenticated RCE
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Qlik Community has released a knowledge base article regarding three vulnerabilities affecting Qlik Sense Enterprise for Windows. The critical vulnerability tracked as CVE-2023-41265 is a HTTP tunneling vulnerability, which could allow an attacker to escalate privileges when successfully exploited.
The high severity vulnerability known as CVE-2023-41266 is a path traversal vulnerability. An unauthenticated, remote attacker could generate an anonymous session, leading to HTTP requests to unauthorised endpoints.
Importantly, the two vulnerabilities can be chained together by an attacker to compromise the server running the Qlik Sense software, with the ability to achieve unauthenticated remote code execution (RCE).
The third vulnerability, CVE-2023-48365, is rated as critical, and exists due to an incomplete fix for CVE-2023-41265. Exploitation in the wild of these three vulnerabilities has been observed.
Exploitation in the wild of CVE-2023-41265, CVE-2023-41266, and CVE-2023-48365
Following the release of full technical details of these exploits, threat actors have been observed exploiting these vulnerabilities in the wild.
Threat updates
| Date | Update |
|---|---|
| 8 Dec 2023 |
Exploitation in the wild has been observed
This cyber alert has been updated to reflect these changes. |
| 4 Sep 2023 |
Technical details of exploit have been published
This cyber alert has been updated to reflect this change. |
Remediation advice
Affected organisations are encouraged to read the Qlik Community advisories Critical Security fixes for Qlik Sense Enterprise for Windows (CVE-2023-41266, CVE-2023-41265) and Critical Security fixes for Qlik Sense Enterprise for Windows (CVE-2023-48365) and to update Qlik Sense Enterprise for Windows to a remediated version below.
- November 2023 IR
- August 2023 Patch 2
- May 2023 Patch 6
- February 2023 Patch 10
- November 2022 Patch 12
- August 2022 Patch 14
- May 2022 Patch 16
- February 2022 Patch 15
- November 2021 Patch 17
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 8 December 2023 10:18 am