ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow Sandbox. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and hot fixes. While we are not currently aware of exploitation against customer instances, we recommend customers promptly apply appropriate updates or upgrade if they have not already done so.
Under specific circumstances, an unauthenticated user can cause code execution within the ServiceNow Sandbox environment. The vulnerability is classified as CWE-653 (insufficient isolation or separation of privileges), which suggests the possibility of escaping the boundaries of an isolated execution environment or bypassing separation mechanisms. ServiceNow has implemented a security update on hosted instances and made patches available to customers and partners using self-hosted installations.
An attacker without any credentials can remotely execute code in the ServiceNow Sandbox environment, which may lead to violation of confidentiality, integrity, and availability of data and resources processed on the platform.
ServiceNow has implemented automatic security updates on hosted instances. Customers using self-hosted installations should immediately apply the appropriate patches or hotfixes indicated by the vendor in KB article KB2693566 available on the ServiceNow Support portal.
ServiceNow AI Platform — versions indicated in vendor references (KB article KB2693566). Affects both ServiceNow-hosted instances and self-hosted installations of customers and partners.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X