Cactus ransomware has been exploiting critical vulnerabilities in the Qlik Sense data analytics solution to get initial access on corporate networks. Qlik Sense supports multiple data sources and allows users to create custom data reports or interactive visualizations that can serve in decision making processes. The product can work both locally or in the cloud. In late August, the vendor released security updates for two critical vulnerabilities affecting the Windows version of the platform. One of the vulnerabilities, a path traversal bug tracked as CVE-2023-41266, could be exploited to generate anonymous sessions and perform HTTP requests to unauthorized endpoints. The second issue, tracked as CVE-2023-41265 and with a critical severity of 9.8, does not require authentication and can be leveraged to elevate privileges and execute HTTP requests on the backend server that hosts the application. On September 20, Qlik discovered that the fix for CVE-2023-41265 was insufficient provided a new update, tracking the issue as a separate vulnerability identified as CVE-2023-48365. In a recent report, cybersecurity company Arctic Wolf warns of Cactus ransomware actively exploiting these flaws on publicly-exposed Qlik Sense instances that remain unpatched. The Cactus ransomware attacks that Arctic Wolf observed exploit the security issues to execute code that causes the Qlik Sense Scheduler service to initiate new processes. The attackers use PowerShell and the Background Intelligent...
Cactus ransomware exploiting Qlik Sense flaws to breach networks
BleepingComputer
·Bill Toulas
·Published Nov 30, 2023
·Updated
Affected Software
3 affected components
Qlik Qlik Sense=2023-41266
Qlik Qlik Sense=2023-41265
Qlik Qlik Sense=2023-48365
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how Cactus ransomware is exploiting vulnerabilities in Qlik Sense to breach corporate networks.
2
What security implications are discussed?
The article highlights the risk of ransomware attacks due to critical vulnerabilities in the Qlik Sense analytics solution.
3
What products or software are affected?
The affected software is Qlik Sense, specifically versions 2023-41266, 2023-41265, and 2023-48365.
4
How are attackers gaining access to networks according to this article?
Attackers are gaining access through critical vulnerabilities found in the Qlik Sense platform.
5
What should organizations using Qlik Sense do in response to this threat?
Organizations should assess their Qlik Sense installations and apply necessary security patches to mitigate the threat from Cactus ransomware.