ZeroHour

CVE-2024-5217

KEVmass

Unauthenticated RCE in ServiceNow Now Platform (Washington DC, Vancouver, Utah)

CISA: ServiceNow Incomplete List of Disallowed Inputs Vulnerability

CVSS 4.0
9.2 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2024-5217 is an input validation flaw — an incomplete list of disallowed inputs (CWE-184/CWE-697) — in ServiceNow's Now Platform, affecting the Washington DC, Vancouver, and earlier releases, with CISA's advisory listing the Utah, Vancouver, and Washington DC releases. Because the flaw is reachable over the network without credentials or user interaction (CVSS 4.0: 9.2 critical, AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker can send crafted input to the platform to trigger it. Successful exploitation yields remote code execution in the context of the Now Platform, with high impact on the confidentiality, integrity, and availability of the instance. Any organization running an affected release is affected, and since Now Platform instances are typically internet-facing, exposure extends beyond internal networks. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2024-07-29 and public reporting indicates cyber agencies have warned that hackers are actively targeting critical ServiceNow vulnerabilities, while EPSS assigns a 99.6% probability of exploitation within 30 days (100th percentile); no public proof-of-concept is known, but the fixes shipped in ServiceNow's June 2024 patching cycle, so unpatched instances remain at risk.

What to do: Inventory all ServiceNow instances, identify those on Washington DC, Vancouver, or earlier releases (including Utah), and apply the relevant June 2024 patching-cycle patches/hot fixes published by ServiceNow immediately, prioritizing internet-facing instances. The flaw is in CISA's KEV catalog (added 2024-07-29) with a 99.6% EPSS score, so treat unpatched instances as actively targeted and, if patching must be delayed, follow vendor mitigation guidance or restrict network access to the instance.

Affected
ServiceNow Now PlatformWashington DC, Vancouver, and earlier releases per the vendor; CISA lists the Utah, Vancouver, and Washington DC Now Platform. Fixed in patches and hot fixes re
Estimated exposure
masstens of thousands of internet-facing Now Platform customer instances serving millions of end users (order-of-magnitude estimate) — ServiceNow is a cloud-hosted, internet-facing ITSM platform used by thousands of large enterprise and government customers that each run multiple instances, so by deployment patterns essentially every instance on Washington DC, Vancouver,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CISA Known Exploited Vulnerability
Affected
ServiceNow Utah, Vancouver, and Washington DC Now Platform
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
servicenow
Products
servicenow
Weakness
CWE-184, CWE-697
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news