ServiceNow has recently revealed three significant vulnerabilities (CVE-2024-4879, CVE-2024-5217, and CVE-2024-5178) impacting various versions of the Now Platform. These flaws enable remote code execution and unauthorized file access without authentication.
With CVSS ratings ranging from 6.9 to 9.3, these vulnerabilities present major risks, including potential data breaches, system takeovers, and operational interruptions. There have been active exploitation attempts by international threat actors against both private and public sector entities, underscoring the seriousness of these issues.
Globally, around 300,000 ServiceNow instances are concentrated primarily in the US, UK, India, and EU, marking them as prominent targets for remote probing. Despite differences in access controls, the extensive use of ServiceNow in enterprise environments highlights its role as a major platform for digital workflows. Additionally, data from search engines suggests that between 13,300 and 23,000 network hosts are at risk, illustrating the wide attack surface available to adversaries for network mapping.
Attackers often exploit vulnerabilities in widely-used applications before patches become available, targeting enterprises discovered through search engine scans and proprietary bots that collect data on web servers, applications, and network devices, providing attackers with valuable insights. The recent vulnerabilities in ServiceNow have enabled unauthenticated remote code execution on approximately 42,000 exposed instances.
While patches are available, over 6,000 sites, mainly in the financial sector, have experienced active exploitation attempts. Attackers are using these vulnerabilities to test for remote code execution and extract database credentials.
Researchers have created detection methods and automated tools to identify affected systems, emphasizing the urgent need for prompt patching and strong security practices to avoid data breaches and unauthorized access.
Following the public disclosure of these vulnerabilities, numerous threat actors launched aggressive scanning campaigns to find exploitable ServiceNow instances. Exploitation of CVE-2024-4879, which allows unauthenticated remote code execution, has been a primary focus. Attackers have utilized a combination of title injection, template injection bypass, and filesystem filter bypass techniques to access ServiceNow data.
Network sensors detected probing requests aimed at identifying vulnerabilities before deploying payloads and validating responses, indicating successful exploitation attempts. Attackers exploited a flaw in login.do to inject malicious code, retrieving the path to the database configuration file and potentially exposing database details. Subsequent payloads queried the “sys_user” table, attempting to extract usernames and passwords. Although most passwords remained hashed and secure, leaked usernames and metadata could facilitate further attacks.
A recently uncovered vulnerability in a major enterprise application was exploited within a week of its disclosure, impacting various organizations worldwide, including energy sectors, data centers, government bodies, and software development firms. This demonstrates the extensive impact of the vulnerability. According to Resecurity, inadequate patch management and outdated systems worsened the problem. While the collected data suggests possible cyberespionage, timely patch releases have helped mitigate further damage.
Threat actors are actively targeting enterprise applications like ServiceNow on the Dark Web, seeking unauthorized access to IT service desks and corporate portals. Initial Access Brokers (IABs) exploit poor network security by monetizing stolen credentials and harvesting data through infostealers.
ServiceNow’s Response
ServiceNow has acknowledged a vulnerability affecting instances running on the Vancouver and Washington, D.C. releases of the Now Platform. An update was promptly deployed on the same day, and subsequent patches have been issued to address the issue.
“We have advised our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they haven’t already,” ServiceNow stated to Cyber Security News. “We will continue to assist customers with patch application as needed.”
It is important to note that these vulnerabilities are not new; they were previously addressed and disclosed in CVE-2024-4879, CVE-2024-5217, and CVE-2024-5178.



