Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-29863. PoCs published by pawlokk.
AI-analyzed exploit summary This PoC exploits a DLL hijacking race condition in QlikView's MSI installer repair mode, allowing local privilege escalation to NT AUTHORITY/SYSTEM by overwriting a dynamically generated temporary file in the user's Temp directory.
Description
A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator.
Exploits (1)
This PoC exploits a DLL hijacking race condition in QlikView's MSI installer repair mode, allowing local privilege escalation to NT AUTHORITY/SYSTEM by overwriting a dynamically generated temporary file in the user's Temp directory.
References (1)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H