logo

CVE-2024-4879, CVE-2024-5178, CVE-2024-5217: ServiceNow MID Server Vulnerabilities Resulting in Unauthorized Code Execution

ID: 41cbea7b-70ae-5413-a693-569508154e1d

STIX ID: report--41cbea7b-70ae-5413-a693-569508154e1d

Feed Name: Arctic Wolf

Threat Score
70/100

Date Published: 2024-07-17

Date Updated: 2026-07-25

Author: Stefan Hostetler

...
...

ServiceNow disclosed three critical vulnerabilities (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) that, when chained, may enable remote code execution against ServiceNow MID servers used as internal proxies; ServiceNow patched hosted instances and published fixed product versions. The advisory rates the issues as high-severity (CVSS 9.3 and 9.2 for two RCEs), reports no active exploitation or public PoCs, and notes successful attacks would generally require access to internal networks where MID servers reside.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.