CVE Vulnerabilities

CVE-2024-4978

Embedded Malicious Code

Published: May 23, 2024 | Modified: Oct 24, 2025
CVSS 3.x
8.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

Weakness

The product contains code that appears to be malicious in nature.

Affected Software

NameVendorStart VersionEnd Version
Javs_viewerJavs8.3.7.250 (including)8.3.7.250 (including)

Potential Mitigations

References