Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-4978 Details

Description

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

Metrics

CVSS 3.x Severity and Vector Strings:

CNA: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentCVSS-B:8.4 HIGHVector:CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4978 CISA-ADPUS Government Resource
https://twitter.com/2RunJack2/status/1775052981966377148 Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentThird Party Advisory
https://www.javs.com/downloads/ Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentBroken LinkProduct
https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/ Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian GovernmentExploitThird Party Advisory
https://twitter.com/2RunJack2/status/1775052981966377148 CVEThird Party Advisory

see all 7 references

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code VulnerabilityMay 29, 2024Jun 19, 2024Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness Enumeration

CWE-IDCWE NameSource
NVD-CWE-OtherWeakness Not in a Standard CWE Category[email protected]
CWE-506Embedded Malicious CodeCybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Affected Products

ProductVersions
javs javs viewer
8.3.7.250

CPE

  • cpe:2.3:a:javs:javs_viewer:8.3.7.250:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

14 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-4978
NVD Published Date:
May 23, 2024
NVD Last Modified:
Jun 17, 2026
Source:
Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
CVE-2024-4978 Details - Not Deferred