CVE-2024-29863

HIGH

Qlik Qlikview <May 2022 SR3 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-29863. PoCs published by pawlokk.

AI-analyzed exploit summary This PoC exploits a DLL hijacking race condition in QlikView's MSI installer repair mode, allowing local privilege escalation to NT AUTHORITY/SYSTEM by overwriting a dynamically generated temporary file in the user's Temp directory.

Description

A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator.

Exploits (1)

nomisec WORKING POC
by pawlokk · poc
https://github.com/pawlokk/qlikview-poc-CVE-2024-29863

This PoC exploits a DLL hijacking race condition in QlikView's MSI installer repair mode, allowing local privilege escalation to NT AUTHORITY/SYSTEM by overwriting a dynamically generated temporary file in the user's Temp directory.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: QlikView 12
Auth required
Prerequisites: QlikView 12 installed · Access to the MSI installer file · Local user access on Windows
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0044
EPSS Percentile 35.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-362
Status published
Published Apr 05, 2024
Tracked Since Feb 18, 2026