CVE Vulnerabilities

CVE-2024-4978

Embedded Malicious Code

Published: May 23, 2024 | Modified: Jan 27, 2025
CVSS 3.x
8.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

Weakness

The product contains code that appears to be malicious in nature.

Affected Software

Name Vendor Start Version End Version
Javs_viewer Javs 8.3.7.250 (including) 8.3.7.250 (including)

Potential Mitigations

References