CISA adds Qlik bugs to exploited vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41265 +1 in the same advisory: …41266 | HTTP Request Tunneling Privilege Escalation in Qlik Sense Enterprise for Windows CVE-2023-41265 is an HTTP request tunneling flaw (CWE-444) in Qlik Sense Enterprise for Windows that lets a remote attacker tunnel additional HTTP requests inside a single raw HTTP request, causing those requests to be executed by the backend server hosting the repository application. Because the tunneled requests are processed in a trusted backend context, the attacker, who needs only low-privileged access according to the CVSS score, achieves privilege elevation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 9.9 critical, scope changed). All Windows releases up to and including May 2023 Patch 3, February 2023 Patch 7, November 2022 Patch 10, and August 2022 Patch 12 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-07 with known ransomware use, EPSS places it in the 100th percentile (88.2% probability of exploitation within 30 days), and reporting ties active exploitation to CACTUS ransomware campaigns as well as 1-day attacks delivering NerbianRAT Linux malware. No public proof-of-concept is known, but exploitation is ongoing, making unpatched, especially internet-exposed, Qlik Sense servers a priority for defenders. Do: Upgrade Qlik Sense Enterprise for Windows to the fixed release for your track: May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13; the August 2023 IR also contains the fix. Per CISA's KEV required action, apply vendor remediations or discontinue use of the product if remediation is unavailable. Given active CACTUS ransomware exploitation of Qlik flaws, prioritize patching internet-exposed servers, restrict access to trusted networks, and check patched and unpatched instances for signs of compromise. | 9.9 group max | 88% | KEV ransomware |
| largeroughly 10,000–100,000 installations worldwide, with likely thousands of internet-exposed Qlik Sense servers |
Full article497 words · extracted from therecord.media · click to collapse
Two vulnerabilities affecting a popular data analytics tool were added to the Cybersecurity and Infrastructure Security Agency’s (CISA) list of exploited bugs this week. On Thursday, CISA added CVE-2023-41265 and CVE-2023-41266 to its catalog, giving federal civilian agencies until December 28 to patch the issues. Both bugs were found this summer in Qlik Sense — a data analytics tool used widely among government organizations and large businesses. The vulnerabilities provide hackers with an entry point into systems and allow them to elevate their privileges. “If the two vulnerabilities are combined and successfully exploited, these issues could lead to a compromise of the server running the Qlik Sense software,” the company said in an advisory on December 5. “Qlik has received reports that this vulnerability may be being used by malicious actors.” CVE-2023-41265 carries a vulnerability severity score of 9.6 and CVE-2023-41266 has a score of 8.2. The vulnerabilities were discovered in August by researchers at cybersecurity firm Praetorian. There are no mitigations and all versions of Qlik Sense Enterprise for Windows before May are vulnerable. Both issues were used in a series of attacks by the Cactus ransomware gang since they were discovered, according to cybersecurity expert Kevin Beaumont and researchers at Arctic Wolf. Viakoo Labs Vice President John Gallagher said Qlik Sense is widely used. “Estimates are there are 40,000 users so as a method of deploying ransomware it’s a good one. Attacks would only be enabled if the threat actor had an internet-exposed instance of Qlik Sense to attach to,” he said. “In that sense most high value targets (with effective security) would be safe assuming Qlik Sense was deployed properly. As with many high severity vulnerabilities it is a race against time in terms of deploying patches.” Qlik warned customers that their tools “should not be exposed to the public internet” and that removing them “reduces the attack surface significantly.” Researchers at Praetorian began to explore issues with Qlik Sense because of the “large number of instances on Shodan (around six thousand externally facing instances), and the high value nature of the software given its usage for data analytics,” they said. “Because organizations use Qlik Sense for data analytics, we hypothesized that they most likely would provide the application with both database credentials and internal network access to corporate environments. This combination of factors made it a high value target for research purposes,” they said. In several posts on the social media site Mastodon, Beaumont said searches on Shodan showed that many U.S-based organizations did have their instances exposed to the internet. In addition to Cactus ransomware actors, several other ransomware gangs are exploiting the bugs, according to Beaumont.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-qlik-bugs-to-kev-list