peter bassill · operator
$ cve CVE-2024-4978 JSON

CVE-2024-4978 KEV

8.4
HIGH · CVSS 3.1 · EPSS 26.9% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2024-06-19.

Description

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

Scoring

CVSS8.4 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
EPSS26.94% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-506
On CISA KEVyes — remediate by 2024-06-19
Public exploitnone known
Published2024-05-23
Last modified2026-06-17

CISA KEV

NameJustice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
Added2024-05-29
Due2024-06-19
Vendor / productJustice AV Solutions / Viewer
Ransomware usenone reported

Affected (1)

VendorProduct
javsjavs viewer

References

→ the Explorer  ·  watch your stack  ·  NVD