ZeroHour
The Recordpublished ()ingested

Critical ServiceNow vulnerabilities being targeted by hackers, cyber agency warns

criticalVulnerability exploited in the wildimportance 60CVE-2024-4879CVE-2024-5178CVE-2024-5217

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-4879
+1 in the same advisory: …5217
Unauthenticated RCE via Jelly Template Injection in ServiceNow Now Platform

CVE-2024-4879 is an improper input validation flaw (CWE-1287) in the ServiceNow Now Platform that permits jelly template injection through UI macros. An unauthenticated attacker can submit crafted input that is improperly handled by the jelly templating engine, resulting in code execution on the instance. Successful exploitation therefore grants unauthenticated remote code execution on affected ServiceNow deployments. Organizations running Utah, Vancouver, or Washington DC Now Platform releases are affected, including the many enterprises and government agencies that expose ServiceNow portals to the internet for employee, customer, or citizen use. The flaw is confirmed exploited in the wild (added to CISA KEV on 2024-07-29), carries a maximal EPSS estimate of 100% probability of exploitation within 30 days, and has no known public PoC.

Do: Apply the patched Now Platform builds for the Utah, Vancouver, and Washington DC release trains per ServiceNow's advisory, as required by the CISA KEV listing. Because exploitation is confirmed and requires no authentication, prioritize internet-facing instances, restrict public access where feasible until patched, and review instance logs for signs of exploitation. Confirm every release train in your environment is covered, since all three (Utah, Vancouver, Washington DC) are affected.

9.3
group max
100% KEV
  • ServiceNow Now Platform (Utah) Utah releases
  • ServiceNow Now Platform (Vancouver) Vancouver releases
  • ServiceNow Now Platform (Washington DC) Washington DC releases
masslikely millions of enterprise users across tens of thousands of deployed Now Platform instances, many of them internet-exposed (order-of-magnitude estimate;…
CVE-2024-5178
ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases.

ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an administrative user to gain unauthorized access to sensitive files on the web application server. The vulnerability is addressed in the listed patches and hot fixes, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

NVD description · AI analysis pending
6.934%
Full article612 words · extracted from therecord.media · click to collapse

Two vulnerabilities affecting popular tools from the cloud company ServiceNow are being exploited by hackers eager to steal sensitive data.

On May 14, security experts at the cybersecurity company AssetNote notified ServiceNow of three serious vulnerabilities that could be chained together and used to siphon important organizational data. Companies use ServiceNow’s cloud-based software for everything from employee management to the automation of business processes, and more. 

ServiceNow released patches for each bug — listed as CVE-2024-4879, CVE-2024-5178 and CVE-2024-5217 — in May and June, but almost immediately after the AssetNote report was released publicly on July 11, a proof-of-concept exploit was published.  

Since then, cybersecurity companies and the federal cybersecurity agency have warned of hackers attempting to exploit the bugs. 

The Cybersecurity and Infrastructure Security Agency (CISA) said on Monday that hackers are specifically targeting CVE-2024-4879 and CVE-2024-5217, giving federal civilian agencies until August 19 to patch the bugs. Both vulnerabilities carry critical severity scores of 9.3 and 9.2 respectively.

Over the last two weeks, reports from Resecurity, Symantec, Imperva and other cybersecurity researchers have outlined hacker attempts to exploit the vulnerabilities, with some warning that anywhere from 13,000 to 42,000 ServiceNow systems may be at risk of compromise. 

The largest number of instances has been identified in the U.S., the United Kingdom, India, and the European Union, according to Resecurity.

Guy Rosenthal, vice president at cybersecurity firm DoControl, said the vulnerabilities let an attacker gain full access to a database and exfiltrate data. 

“The vulnerabilities also allowed a cybercriminal to read files, which means that the attacker could traverse a system and manipulate file paths and have a wide berth to go anywhere and access anything that they’d like to see or steal,” he said. 

“These three vulnerabilities gave the attacker free reign within the ServiceNow platform.”

Resecurity said it has been closely monitoring activity from foreign threat actors seeking to extract data from both private sector companies and government agencies globally.

“The activity was timely contained by the vendor, several episodes of malicious cyber activity were identified during the exposure window, and could be interpreted as limited,” the researchers said.

The company saw mass scanning — where hackers scan the internet for vulnerable ServiceNow instances — once information about the bugs was released. Hackers typically probed systems to check if they were vulnerable before attempting to exploit the bugs, often starting with CVE-2024-4879. 

Resecurity found multiple organizations across several countries and verticals affected, including an energy company, a government agency of a country in the Middle East and a software development firm, among others. 

“Notably, some of them were not aware of the released patch, and in some cases used outdated or poorly maintained instances by their developers and software engineers,” the researchers said.

“There has been identified chatter on multiple underground forums on the Dark Web highlighting threat actors seeking compromised access to IT service desks, corporate portals, and other enterprise systems that typically provide remote access to employees and contractors.”

Resecurity also warned of initial access brokers gaining entry to systems and then selling the access on the dark web, using infostealers and other tools to gain a foothold. 

Cybersecurity firm Imperva said it saw exploitation attempts “in over 6,000 sites across various industries, especially in the financial services industry” — with attackers “primarily leveraging automated tools to target login pages.” 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/critical-servicenow-vulnerabilities-hackers-cisa