CVE-2024-4978
Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 19 June 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.
- CVSS 4.0
- 8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 26.94% probability · 98th percentile
- CISA KEV
- Listed 29 May 2024 · due 19 June 2024
- Weakness
- CWE-506
- Affected
- javs/javs viewer
- Source
- 9119a7d8-5eab-497f-8521-727c672e3725
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Please follow the vendor’s instructions as outlined in the public statements at https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack#remediation and https://www.javs.com/downloads; https://nvd.nist.gov/vuln/detail/CVE-2024-4978
References
- https://twitter.com/2RunJack2/status/1775052981966377148Third Party Advisory
- https://www.javs.com/downloads/Broken Link, Product
- https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/Exploit, Third Party Advisory
- https://twitter.com/2RunJack2/status/1775052981966377148Third Party Advisory
- https://www.javs.com/downloads/Broken Link, Product
- https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4978US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.