ZeroHour

CVE-2023-41265

KEV ransomwarelarge1

HTTP Request Tunneling Privilege Escalation in Qlik Sense Enterprise for Windows

CISA: Qlik Sense HTTP Tunneling Vulnerability

CVSS 3.1
9.9 critical
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2023-41265 is an HTTP request tunneling flaw (CWE-444) in Qlik Sense Enterprise for Windows that lets a remote attacker tunnel additional HTTP requests inside a single raw HTTP request, causing those requests to be executed by the backend server hosting the repository application. Because the tunneled requests are processed in a trusted backend context, the attacker, who needs only low-privileged access according to the CVSS score, achieves privilege elevation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.9 critical, scope changed). All Windows releases up to and including May 2023 Patch 3, February 2023 Patch 7, November 2022 Patch 10, and August 2022 Patch 12 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-07 with known ransomware use, EPSS places it in the 100th percentile (88.2% probability of exploitation within 30 days), and reporting ties active exploitation to CACTUS ransomware campaigns as well as 1-day attacks delivering NerbianRAT Linux malware. No public proof-of-concept is known, but exploitation is ongoing, making unpatched, especially internet-exposed, Qlik Sense servers a priority for defenders.

What to do: Upgrade Qlik Sense Enterprise for Windows to the fixed release for your track: May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13; the August 2023 IR also contains the fix. Per CISA's KEV required action, apply vendor remediations or discontinue use of the product if remediation is unavailable. Given active CACTUS ransomware exploitation of Qlik flaws, prioritize patching internet-exposed servers, restrict access to trusted networks, and check patched and unpatched instances for signs of compromise.

Affected
Qlik Sense Enterprise for WindowsMay 2023 Patch 3 and earlier (fixed in May 2023 Patch 4)
Qlik Sense Enterprise for WindowsFebruary 2023 Patch 7 and earlier (fixed in February 2023 Patch 8)
Qlik Sense Enterprise for WindowsNovember 2022 Patch 10 and earlier (fixed in November 2022 Patch 11)
Qlik Sense Enterprise for WindowsAugust 2022 Patch 12 and earlier (fixed in August 2022 Patch 13)
Estimated exposure
largeroughly 10,000–100,000 installations worldwide, with likely thousands of internet-exposed Qlik Sense servers — Qlik Sense Enterprise for Windows is a widely deployed on-premises business intelligence platform with a large global installed base of enterprise deployments (each typically serving dozens to hundreds of internal users), and public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

CISA Known Exploited Vulnerability
Affected
Qlik Sense
Required action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
qlik
Products
qlik sense
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news