Qlik Sense flaws exploited in Cactus ransomware campaign
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41265 +1 in the same advisory: …41266 | HTTP Request Tunneling Privilege Escalation in Qlik Sense Enterprise for Windows CVE-2023-41265 is an HTTP request tunneling flaw (CWE-444) in Qlik Sense Enterprise for Windows that lets a remote attacker tunnel additional HTTP requests inside a single raw HTTP request, causing those requests to be executed by the backend server hosting the repository application. Because the tunneled requests are processed in a trusted backend context, the attacker, who needs only low-privileged access according to the CVSS score, achieves privilege elevation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.9 critical, scope changed). All Windows releases up to and including May 2023 Patch 3, February 2023 Patch 7, November 2022 Patch 10, and August 2022 Patch 12 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-07 with known ransomware use, EPSS places it in the 100th percentile (88.2% probability of exploitation within 30 days), and reporting ties active exploitation to CACTUS ransomware campaigns as well as 1-day attacks delivering NerbianRAT Linux malware. No public proof-of-concept is known, but exploitation is ongoing, making unpatched, especially internet-exposed, Qlik Sense servers a priority for defenders. Do: Upgrade Qlik Sense Enterprise for Windows to the fixed release for your track: May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13; the August 2023 IR also contains the fix. Per CISA's KEV required action, apply vendor remediations or discontinue use of the product if remediation is unavailable. Given active CACTUS ransomware exploitation of Qlik flaws, prioritize patching internet-exposed servers, restrict access to trusted networks, and check patched and unpatched instances for signs of compromise. | 9.9 group max | 88% | KEV ransomware |
| largeroughly 10,000–100,000 installations worldwide, with likely thousands of internet-exposed Qlik Sense servers | |
| CVE-2023-48365 | HTTP Request Smuggling/Tunneling in Qlik Sense Allows Privilege Escalation Qlik Sense contains an HTTP tunneling flaw (CWE-444, inconsistent interpretation of HTTP requests, i.e., HTTP request smuggling) in which the application's tunneling component and the backend server hosting the software disagree about HTTP request boundaries. An attacker triggers it by sending crafted HTTP requests through the tunneling mechanism of an affected Qlik Sense deployment. Exploitation lets the attacker escalate privileges and execute HTTP requests against the backend server, reaching internal services and interfaces that should only be accessible to the application. Any organization running an affected Qlik Sense deployment is exposed, with internet-facing instances at greatest risk. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-01-13 with ransomware use known, and EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile); no public PoC is known. Do: Apply Qlik's remediation for CVE-2023-48365 per the vendor's security instructions, or discontinue use of the product if mitigations are unavailable (CISA KEV required action). Prioritize internet-exposed Qlik Sense servers, and given known ransomware use, hunt for indicators such as unexpected requests arriving at the backend server, anomalous authentication activity, and lateral movement originating from the Qlik host. | 9.9 | 24% | KEV ransomware |
| large≈tens of thousands of enterprise deployments, with on the order of a few thousand Qlik Sense servers exposed to the internet |
Full article423 words · extracted from helpnetsecurity.com · click to collapse
Attackers are exploiting three critical vulnerabilities in internet-facing Qlik Sense instances to deliver Cactus ransomware to target organizations, Arctic Wolf researchers have warned.

The exploited vulnerabilities
Qlik Sense is a business intelligence and data analytics solution popular with governmental organizations and enterprises.
Attackers wielding Cactus ransomware have previously been seen breaching large commercial organizations by exploiting vulnerabilities in VPN appliances. The group also engages in double-extortion tactics.
“Based on patch level Qlik Sense is likely being exploited either via the combination or direct abuse of CVE-2023-41266, CVE-2023-41265 or potentially CVE-2023-48365 to achieve code execution,” Arctic Wolf Labs researchers shared.
CVE-2023-41266 is a path traversal vulnerability that could allow an attacker to generate an anonymous session through malicious HTTP requests and send further requests to unauthorized endpoints.
CVE-2023-41265 is an HTTP tunnelling vulnerability that could elevate attacker’s privileges to execute HTTP requests on the hosting backend server.
CVE-2023-48365 has been issued later, as the fix for CVE-2023-41265 could be bypassed by modifying the HTTP request.
“The Qlik Sense vulns were discovered in August and September by Praetorian, an InfoSec vendor – unfortunately they published a full exploit chain, which the ransomware group has lifted wholesale,” security researcher Kevin Beaumont noted.
The attack
After a successful exploitation, the attackers leveraged PowerShell and the Background Intelligent Transfer Service (BITS) to download the following tools that allow them to gain persistence and remotely control the system:
- Renamed ManageEngine UEMS executables posing as Qlik files
- The AnyDesk remote solution, pulled from the official site
- A Plink (PuTTY Link) binary renamed to putty.exe
The attackers also uninstalled Sophos’ endpoint security solution, changed the admin password, set up an RDP tunnel via Plink and used it for lateral movement, analyzed disk space with WizTree and used rclone (renamed as svchost.exe) to exfiltrate data. Finally, they managed to deploy Cactus ransomware to some of the affected systems.
“Based on significant overlaps observed in all intrusions we attribute all of the described attacks to the same threat actor,” the researchers concluded.
Beaumont says that he has seen another ransomware group exploiting Qlik Sense. “Currently it is a very low number of attacks so you might want to patch,” he added.
Patches are available
Qlik has released the patches in August and September and customers are urged to upgrade Qlik Sense Enterprise for Windows to the following versions:
- August 2023 Patch 2
- May 2023 Patch 6
- February 2023 Patch 10
- November 2022 Patch 12
- August 2022 Patch 14
- May 2022 Patch 16
- February 2022 Patch 15
- November 2021 Patch 17
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/12/01/qlik-sense-cactus-ransomware/