Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

MID Server patch upgrade includes which type of files

Ayush10
Tera Contributor

We have ServiceNow MID Servers in our environment, and periodic MID Server upgrades/patches are installed. During these upgrades, Carbon Black frequently blocks some of the files being deployed, which results in the MID Server going down. We then need to perform additional troubleshooting and coordinate with the Carbon Black team to review and approve the blocked files before the MID Server can be brought back online.

Could someone please help clarify the following:

  • What types of files are downloaded and installed during a MID Server upgrade/patch?
  • From which locations/directories are these files downloaded, extracted, and executed during the upgrade process?
  • Which folders, file types, or processes should be considered for whitelisting in Carbon Black to prevent future upgrade failures?
  • Are there any standard ServiceNow recommendations for antivirus/endpoint protection exclusions related to MID Server upgrades?
Any guidance and recommended Carbon Black exclusions would be greatly appreciated.
1 REPLY 1

KPNow
Mega Guru

Hi @Ayush10 :

When a MID Server upgrades, it pulls down updated binaries such as new Java Runtime Environment (JRE) packages, ServiceNow Java wrappers, and helper scripts directly from ServiceNow's official install servers (install.servicenow.com or *.servicenow.com). During this process, files are written, extracted, and executed directly within the host machine’s local MID installation directory (specifically inside the agent, agent/jre/bin, agent/bin, and agent/work subfolders), as well as the OS temporary directory. Security tools like Carbon Black (as you mentioned) get aggressive because they see an unprivileged application writing executable .exe, .dll, and Java files to disk and immediately attempting to spawn child processes, which triggers a high-severity "behavioral block" and corrupts the upgrade.

To put a stop to these upgrade breakages, ServiceNow recommends giving the MID Server's installation footprint a clear runway rather than playing whack-a-mole with individual files. In Carbon Black, your security team should set up path-based and process-based exclusions. Specifically, whitelist the entire parent MID installation directory using a recursive wildcard rule (e.g., C:\ServiceNow\agent\* on Windows or the equivalent on Linux). Equally important is granting full execution and child-process-spawning privileges to the core binaries: wrapper-windows-x86-64.exe (or the Linux equivalent) and java.exe located inside agent/jre/bin/.
Whitelisting these core executables and allowing them to run, write files, and launch child processes will keep Carbon Black happy and allow your MID Servers to patch automatically without manual intervention.
 
Hope this helps you.