CVE-2024-4879

CRITICAL KEV NUCLEI

ServiceNow - RCE

Title source: llm

Description

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

Exploits (11)

exploitdb WORKING POC
by İbrahimsql · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52410
nomisec SCANNER 26 stars
by Brut-Security · remote
https://github.com/Brut-Security/CVE-2024-4879
nomisec SCANNER 10 stars
by bigb0x · remote
https://github.com/bigb0x/CVE-2024-4879
nomisec SCANNER 5 stars
by NoTsPepino · remote
https://github.com/NoTsPepino/CVE-2024-4879-CVE-2024-5217-ServiceNow-RCE-Scanning
nomisec WORKING POC 4 stars
by gh-ost00 · remote
https://github.com/gh-ost00/CVE-2024-4879
nomisec WORKING POC 4 stars
by Mr-r00t11 · remote
https://github.com/Mr-r00t11/CVE-2024-4879
github WORKING POC 2 stars
by Pr0t0c01 · pythonpoc
https://github.com/Pr0t0c01/CVEs/tree/main/ServiceNow_CVE-2024-4879
nomisec WORKING POC 1 stars
by Praison001 · remote
https://github.com/Praison001/CVE-2024-4879-ServiceNow
nomisec WORKING POC
by 0xWhoami35 · remote
https://github.com/0xWhoami35/CVE-2024-4879
nomisec WORKING POC
by jdusane · remote
https://github.com/jdusane/CVE-2024-4879

Nuclei Templates (1)

ServiceNow UI Macros - Template Injection
CRITICALVERIFIEDby DhiyaneshDk,ritikchaddha
Shodan: http.favicon.hash:"1701804003" || http.title:"servicenow"
FOFA: icon_hash=1701804003 || title="servicenow"

Scores

CVSS v3 9.8
EPSS 0.9435
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-07-29
VulnCheck KEV 2024-07-23
InTheWild.io 2024-07-29
ENISA EUVD EUVD-2024-44451
CWE
CWE-1287
Status published
Products (2)
servicenow/servicenow utah (46 CPE variants)
servicenow/servicenow vancouver (4 CPE variants)
Published Jul 10, 2024
KEV Added Jul 29, 2024
Tracked Since Feb 18, 2026