logo

CVE-2024-4879, CVE-2024-5178, CVE-2024-5217

ID: baa48fc5-54a7-5bba-b087-d8488d2b9386

STIX ID: report--baa48fc5-54a7-5bba-b087-d8488d2b9386

Feed Name: Arctic Wolf Blog

Threat Score
70/100

Date Published: 2024-07-17

Date Updated: 2026-04-27

...
...

On July 10, 2024 ServiceNow disclosed three critical vulnerabilities (CVE-2024-4879, CVE-2024-5178, CVE-2024-5217) that Assetnote demonstrated could be chained to achieve remote code execution on ServiceNow MID servers and allow unauthorized file access; affected releases have fixed versions and ServiceNow patched hosted instances in June 2024. While CVSS scores for two RCE issues are very high, there are no confirmed in-the-wild exploit reports or public PoC code, and exploitation typically requires access to internal networks where MID servers are deployed, so organizations are advised to apply vendor patches promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.