Permissions, Privileges, and Access Controls in Qlik Sense Enterprise for Windows - CVE-2024-55579

 

Permissions, Privileges, and Access Controls in Qlik Sense Enterprise for Windows - CVE-2024-55579

Published: June 11, 2025


Vulnerability identifier: #VU111080
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-55579
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system

The vulnerability exists due to application does not properly impose security restrictions. A remote attacker on the local network can use Connectors feature to execute arbitrary .exe files on the server. 


Affected software

Qlik Sense Enterprise for Windows

How to mitigate CVE-2024-55579

Install updates from vendor's website.

Qlik Sense Enterprise for Windows - addressed in versions August 2023 Patch 16, November 2024, May 2024 Patch 10, February 2024 Patch 14, February 2023 Patch 15, November 2023 Patch 16, May 2023 Patch 18

External References

Related Security Bulletins