Count(er) Strike is a high-severity access control vulnerability in ServiceNow Now Platform caused by a logical flaw in conditional ACL evaluation. Under specific ACL configurations, unauthenticated or authenticated users can issue range query requests that do not directly return protected rows but still reveal whether matching records exist and allow inference of underlying instance data that should not be accessible. Research associated the issue with count-based blind inference behavior, including use of filter-driven queries that separate row visibility from count responses. The flaw affects Now Platform versions older than Xanadu and Yokohama and is fundamentally a broken access control condition in which query behavior can disclose protected information despite intended ACL restrictions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ServiceNow blind inference issue involving count behavior that can confirm matching records exist without returning the records themselves.
A ServiceNow count-based blind inference issue involving the filterText parameter that can reveal whether matching records exist without returning the rows themselves.
ServiceNow Now Platform data inference vulnerability via misconfigured/conditional ACL rules, potentially enabling data exposure/exfiltration.
A high-severity ServiceNow Now Platform vulnerability caused by a logical flaw in ACL rule evaluation that can allow unauthenticated or authenticated attackers to gain unauthorized access to sensitive data, including credentials, via range query requests under specific ACL configurations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.