MDSec found that a compromised ServiceNow tenant can provide a high-impact route into connected enterprise infrastructure, including on-premises networks reached through Management, Instrumentation, and Discovery (MID) Servers. During red-team engagements, researchers gained initial access through hijacked user sessions, exposed MID Server configuration credentials, and simulated exploitation of major ServiceNow zero-days, then abused excessive platform privileges to expand control.
The assessment identified at least 24 ServiceNow roles with potential privilege-escalation paths, including catalog_admin, import_admin, and sn_cmdb_editor; action_designer could serve as an intermediary in escalation chains. MDSec also demonstrated persistence, evasion, credential access, and command execution through MID Servers, and developed SnowFall, a proof-of-concept fileless C2 framework using scheduled ServiceNow jobs and Glide scripts. The firm reported immature monitoring, incident-response, and containment capabilities across assessed organizations, leaving ServiceNow deployments attractive targets for enterprise compromise.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
MDSec reported that attackers could evade ServiceNow detections through role inheritance, audit-field manipulation, brief privileged-role assignments, and deletion of activity records. It identified login, role, flow, script-execution, and transaction-history records as potential evidence of malicious activity.
MDSec reported that MID Server configuration and credential-decryption functions could expose Windows discovery credentials, SSH credentials, and API keys. It described onward movement from a compromised MID Server through discovery credentials to SCCM or comparable privileged infrastructure, including across otherwise separated Active Directory forests connected to one tenant.
MDSec demonstrated that a compromised ServiceNow tenant could execute code on MID Servers by uploading custom JAR plugins through the ECC Queue, and could send operating-system commands to a specific MID Server using ECC Queue records.
MDSec reported that ServiceNow tables and attachments exposed login history, incident data, red-team reports, and detection-triage information. In one engagement, a ServiceNow CyberArk REST Message enabled retrieval of passwords from an accessible CyberArk Safe, including a tenant break-glass administrator account.
MDSec demonstrated persistence through modified business rules and scheduled jobs that could recreate and elevate a backdoor user. It also described SnowFall, a fileless command-and-control framework using scheduled jobs to retrieve, execute, and return Glide-script commands through an external redirector.
MDSec identified at least 24 distinct ServiceNow roles that could be leveraged for privilege escalation, including catalog_admin, import_admin, and sn_cmdb_editor. Across three engagements, it found more than 10,000 users assigned sn_cmdb_editor.
MDSec reported that an import_admin MID service account could use the ServiceNow REST API to create and trigger transform maps containing elevated scripts. The technique could remove the account's web_service_access_only restriction, grant an intermediary role, and enable interactive logon.
During another engagement, MDSec found a ServiceNow config.xml file on a file share containing credentials for a MID Server account with the import_admin role.
MDSec abused catalog_admin's inherited user_criteria_admin privileges to run elevated Glide scripts, assigned action_designer to the compromised HR user, and used Workflow Studio to obtain administrative privileges.
In one engagement, MDSec phished an HR employee, extracted the employee's ServiceNow session cookie, and found the account had the catalog_admin role.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.