By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Three CVSS 10.0 ServiceNow Flaws Allow Unauthenticated Code Execution

ServiceNow has released patches for four critical security vulnerabilities affecting its AI Platform, with three of these flaws receiving the highest possible severity score of 10.0 on the Common Vulnerability Scoring System (CVSS). These three vulnerabilities, identified as CVE-2024-29973, CVE-2024-29972, and CVE-2024-29971, could allow an unauthenticated attacker to execute arbitrary code and Structured Query Language (SQL) commands on affected systems under specific conditions. The fourth vulnerability, CVE-2024-29974, is rated as high severity. ServiceNow stated that it has already deployed a security update to its hosted instances and has provided the necessary patches to its partners and customers operating self-hosted environments. Organizations that run their own ServiceNow instances and have not yet applied these updates remain at risk. The company did not specify the exact circumstances required for exploitation but emphasized the critical nature of the flaws. The CVSS scoring system is an open industry standard for assessing the severity of computer system vulnerabilities. A score of 10.0 indicates a critical vulnerability that is highly exploitable and can lead to severe consequences, such as complete system compromise. The ability for an unauthenticated attacker to exploit these flaws is particularly concerning, as it means an attacker does not need any prior access or credentials to initiate an attack. The potential for arbitrary code execution allows an attacker to run any command on the vulnerable server, which could lead to data theft, system disruption, or the installation of malware. Similarly, SQL injection vulnerabilities can be used to manipulate or extract sensitive data from databases. ServiceNow is a leading provider of cloud-based IT service management (ITSM) software, helping organizations manage digital workflows for enterprise operations. Its AI Platform integrates artificial intelligence capabilities into its services to automate tasks and improve efficiency. The company's proactive patching and communication underscore the severity of these vulnerabilities and the importance of timely security updates. Customers are strongly advised to apply the provided patches immediately to mitigate the risk of exploitation. The disclosure of these critical vulnerabilities highlights the ongoing challenges in securing complex enterprise software platforms, especially those incorporating advanced technologies like AI, which can introduce new attack vectors. The swift response from ServiceNow in issuing patches is a positive indicator, but the responsibility now lies with end-users to implement these fixes promptly to protect their sensitive data and operations.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.