CVE-2024-36077
Last modified
CVE-2024-36077 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands on the server. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands on the server. This affects February 2024 Patch 3 (14.173.3 through 14.173.7), November 2023 Patch 8 (14.159.4 through 14.159.13), August 2023 Patch 13 (14.139.3 through 14.139.20), May 2023 Patch 15 (14.129.3 through 14.129.22), February 2023 Patch 13 (14.113.1 through 14.113.18), November 2022 Patch 13 (14.97.2 through 14.97.18), August 2022 Patch 16 (14.78.3 through 14.78.23), and May 2022 Patch 17 (14.67.7 through 14.67.31). This has been fixed in May 2024 (14.187.4), February 2024 Patch 4 (14.173.8), November 2023 Patch 9 (14.159.14), August 2023 Patch 14 (14.139.21), May 2023 Patch 16 (14.129.23), February 2023 Patch 14 (14.113.19), November 2022 Patch 14 (14.97.19), August 2022 Patch 17 (14.78.25), and May 2022 Patch 18 (14.67.34).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-36077?
How severe is CVE-2024-36077?
How do I fix CVE-2024-36077?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-36071Samsung Magician 8.0.0 on Windows allows an admin to escalat…6.3
- CVE-2024-36072Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys…9.8
- CVE-2024-36073Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys…7.2
- CVE-2024-36074Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys…7.2
- CVE-2024-36075The CoSoSys Endpoint Protector through 5.9.3 and Unify agent…6.5
- CVE-2024-36076Cross-Site WebSocket Hijacking in SysReptor from version 202…8.8
- CVE-2024-36078In Zammad before 6.3.1, a Ruby gem bundled by Zammad is inst…6.7
- CVE-2024-36079An issue was discovered in Vaultize 21.07.27. When uploading…6.5
- CVE-2024-3608The Product Designer plugin for WordPress is vulnerable to u…5.3
- CVE-2024-36080Westermo EDW-100 devices through 2024-05-03 have a hidden ro…9.8
- CVE-2024-36081Westermo EDW-100 devices through 2024-05-03 allow an unauthe…9.8
- CVE-2024-36082SQL injection vulnerability in Music Store - WordPress eComm…6.5
Are you affected by CVE-2024-36077?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
