CVE-2024-4978
Justice AV Solutions Viewer: (JAVS) Viewer Installer Embedded Malicious Code
As of , CVE-2024-4978 in Justice AV Solutions Viewer is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.
- Exploited
- Yes: CISA listed it on 29 May 2024
- US federal deadline
- 19 June 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.27Higher than 97% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.00 on 29 May 2024EPSS on the day CISA listed it.
- Public exploit
- None foundNeither Metasploit nor Exploit-DB lists one.
- Fix
- Vendor advice: www.rapid7.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA's required action
- www.rapid7.comPlease follow the vendor’s instructions as outlined in the public statements at
What the flaw is
Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.
CISA's description
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.
The CVE record's description, from cisa-cg
- CVE published
- 23 May 2024
- Assigned by
- cisa-cg
- CVSS
- 8.7 High (CVSS 4.0, from the CNA)
- CWE-506
- Embedded Malicious Code
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- no
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org