Headline
CVE-2021-41989: Vulnerability-Disclosures/MNDT-2023-0001.md at master · mandiant/Vulnerability-Disclosures
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
MNDT-2023-0001****Description
Qlik QlikView for Windows contains a local privilege escalation vulnerability which affected version 12.60.20100.0.
Impact
High - Exploiting the vulnerability will give a local unprivileged attacker SYSTEM level privileges.
Exploitability
Medium - Any authenticated local user can exploit the vulnerability and an exploit is trivial to produce.
CVE Reference
CVE-2021-41989
Common Weakness Enumeration
CWE-379: Creation of Temporary File in Directory with Insecure Permissions
Common Vulnerability Scoring System
Base Score: 7.8 - Vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Technical Details
The installation of the agent uses the Windows Installer framework and an MSI file is cached in c:\windows\installer. An unprivileged user can trigger a repair operation, either by using the Windows Installer API or by running "msiexec.exe /fa c:\windows\installer\[XXXXX].msi".
Running a repair operation will trigger a number of file operations in the %TEMP% folder of the user triggering the repair. Some of these operations will be performed from a SYSTEM context (started via the Windows Installer service), including the execution of temporary files.
Resolution
The issue was fixed with the May 2022 Initial Release to Service Release 1. Update to address the vulnerability.
Discovery Credits
- Ronnie Salomonsen, Mandiant
Disclosure Timeline
- 05-Oct-2021 - Issue reported to Qlik
- 17-Nov-2021 - Issue confirmed by Qlik and a fix scheduled for Oct 5, 2022.
- 05-Oct-2022 - Patched version released by Qlik
References
- Qlik Security Advisory
- Mitre CVE-2021-41989