SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-4978

Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability

KEVHIGH 8.7EPSS 26.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 19 June 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

CVSS 4.0
8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
26.94% probability · 98th percentile
CISA KEV
Listed 29 May 2024 · due 19 June 2024
Weakness
CWE-506
Affected
javs/javs viewer
Source
9119a7d8-5eab-497f-8521-727c672e3725

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please follow the vendor’s instructions as outlined in the public statements at https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack#remediation and https://www.javs.com/downloads; https://nvd.nist.gov/vuln/detail/CVE-2024-4978

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.