CVE-2024-55579

Published Dec 9, 2024

Last updated 3 months ago

Overview

Description
An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2024 Patch 10, February 2024 Patch 14, November 2023 Patch 16, August 2023 Patch 16, May 2023 Patch 18, and February 2023 Patch 15.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-863

Social media

Hype score
Not currently trending
  1. CVE-2024-55579 (CVSS:8.8, HIGH) is Awaiting Analysis. An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network ..https://t.co/bZcuo14KYN #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    14 Dec 2024

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-55579 (CVSS:8.8, HIGH) is Awaiting Analysis. An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network ..https://t.co/bZcuo14KYN #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    12 Dec 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨🚨CVE-2024-55579, 55580: Qlik Sense Users Face Serious Security Risk ⚠️These vulnerabilities could allow unprivileged users with network access to compromise the server, potentially leading to remote code execution (RCE) and broken access control (BAC). ZoomEye… https://t.co/

    @zoomeye_team

    9 Dec 2024

    459 Impressions

    1 Retweet

    6 Likes

    1 Bookmark

    0 Replies

    1 Quote

  4. #CybersecurityNews ⚠️ Critical vulnerabilities in Qlik Sense for Windows! CVE-2024-55579 & CVE-2024-55580 allow unprivileged users to execute commands, jeopardizing server integrity. Patch now! #QlikSenseSecurity #DataIntegrityThreats #RemoteCodeExecutio… https://t.co/FHNRnpV

    @TweetThreatNews

    9 Dec 2024

    3 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. A new vulnerability with increased severity was disclosed for Qlik Sense Enterprise (CVE-2024-55579) https://t.co/EFCHCFRxo4

    @vuldb

    9 Dec 2024

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2024-55579,-55580: RCE and BAC in Qlik Sense, 7.5, 8.8 rating❗️ Vulns discovered in Qlik Sense allow hackers to run EXE files on the server, or remotely execute commands. Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/1lNGyxqx0J #cybersecurity #vulnerability_map

    @Netlas_io

    9 Dec 2024

    526 Impressions

    2 Retweets

    9 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-55579 Arbitrary EXE Execution Vulnerability in Qlik Sense Enterprise In Qlik Sense Enterprise for Windows until a fix in November 2024, a vulnerability was found. A user without special permissions, but ... https://t.co/Fxk00tHooI

    @VulmonFeeds

    9 Dec 2024

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. [CVE-2024-55579: HIGH] Qlik Sense Enterprise for Windows had a critical cyber security issue that allowed execution of arbitrary EXE files by an unprivileged user, fixed in updates from February 2023 to November ...#cybersecurity,#vulnerability https://t.co/Y4LYx3OR7D https://t.c

    @CveFindCom

    9 Dec 2024

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2024-55579 An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection object… https://t.co/dvpHujLmrB

    @CVEnew

    9 Dec 2024

    432 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes