CVE-2024-4978

CVE Published 2024-05-23
Related CWE(s) CWE-506: Embedded Malicious Code
Related Vendor(s) javs
Related Product(s) javs_viewer
Exploitation Reported (CISA KEV) 2024-05-29
CVSS 3 Base Score 8.4 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References