Junglewise Threat Intelligence

CVE-2024-4978: Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability

CVE-2024-4978 · Severity: critical · CVSS 8.4 · Exploited in the wild · Published 2024-05-29

Executive brief

Justice AV Solutions (JAVS) Viewer installer version 8.3.7.250-1 contains a malicious version of ffmpeg.exe (named fffmpeg.exe) that functions as a backdoor. When executed, the binary establishes a connection to a malicious command-and-control (C2) server, allowing for unauthorized PowerShell command execution.

Affected products

  • Justice AV Solutions (JAVS) Viewer Setup 8.3.7.250-1

Timeline

  • 2024-05-23: disclosed: Rapid7 published a blog post regarding the backdoored software.
  • 2024-05-29: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) Catalog.
  • 2024-05-29: exploited: Reported as exploited in the wild.