← Vulnerability feed

Vulnerability record · CVE-2024-4978 · published 23 May 2024

CVE-2024-4978: JAVS Viewer installer ships backdoored binary with forged signature

Javs · Javs Viewer

The Justice AV Solutions Viewer Setup 8.3.7.250-1 installer contains an embedded malicious binary signed with an unexpected Authenticode signature, making it a supply-chain compromise of the vendor's download. Because the tampered installer is the legitimate distribution channel, anyone who downloads and runs it may be running attacker-controlled code.

8.7 CVSS 4.0 High CISA KEV since 29 May 2024 EPSS 27% · top 2.0% CWE-506 · CWE-506
8.7CVSS 4.0 base score
27%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a confirmed supply-chain backdoor in a signed installer, listed in CISA KEV with high EPSS and an exploit-tagged reference.

What it is

The Justice AV Solutions Viewer Setup 8.3.7.250-1 installer contains an embedded malicious binary signed with an unexpected Authenticode signature, making it a supply-chain compromise of the vendor's download. Because the tampered installer is the legitimate distribution channel, anyone who downloads and runs it may be running attacker-controlled code.

Impact

An attacker gains execution of unauthorized PowerShell commands on the host, with the CVSS vector indicating high confidentiality, integrity and availability impact to both the vulnerable system and subsequent systems.

Attack surface

Reached over the network by obtaining and executing the trojanized installer; the vector requires high privileges (PR:H) and user action (UI:A) to run the setup, and attack complexity is rated low.

Exploitation

CVE-2024-4978 is listed in CISA KEV (added 2024-05-29) and has an EPSS 30-day probability of roughly 0.269 (97.9th percentile), with a reference tagged Exploit; no ransomware campaign use is documented.

What to do

  • Remove or quarantine any installed JAVS Viewer 8.3.7.250-1 and reimage affected endpoints; treat the installer as untrusted.
  • Follow CISA KEV required action: apply vendor mitigations or discontinue use of the product if no fixed build is available.
  • Verify Authenticode signatures on all vendor installers against expected publisher certificates before deployment.
  • Restrict software installation privileges and block untrusted download sources for AV/meeting-room software.
  • Hunt for and remove persistence or scheduled tasks created by the installer, and rotate credentials exposed on affected hosts.

Detection

  • Search endpoint telemetry for execution of the JAVS Viewer Setup 8.3.7.250-1 installer and any child PowerShell processes it spawns.
  • Alert on PowerShell command lines and network callbacks originating from JAVS Viewer install paths or processes.
  • Audit Authenticode signatures on installed binaries for unexpected or mismatched publishers.
  • Monitor for the known malicious binary hash and related indicators from the Rapid7 advisory across EDR and proxy logs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-4978 to the Known Exploited Vulnerabilities catalog on 29 May 2024 as "Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 19 June 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-4978 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-8398DAEMON Tools Lite installers trojanized via supply chain compromiseAttackers breached AVB Disc Soft's build or distribution infrastructure and trojanized three signed binaries (DTHelper.exe, DiscSoftBusServiceLite.ex…KEVEPSS 0.96%analysed9.3CVE-2026-48027Nx Console VS Code extension shipped with embedded malicious codeA malicious version of the Nx Console extension, 18.95.0, was published to the Visual Studio Marketplace and OpenVSX and remained downloadable for ro…KEVEPSS 1.3%analysed9.6CVE-2026-45321TanStack npm packages published with credential-stealing malware via CI/CD chainEighty-four malicious versions across 42 @tanstack/* npm packages were published on 2026-05-11 using the legitimate GitHub Actions OIDC trusted-publi…KEVEPSS 1.1%analysed9.4CVE-2026-33634Trivy and trivy-action supply chain compromise via malicious release and tagsA threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in aquasecurity/trivy-acti…KEVEPSS 1.7%analysed7.5CVE-2025-54313eslint-config-prettier npm package ships malicious install scriptVersions 8.10.1, 9.1.1, 10.1.6 and 10.1.7 of eslint-config-prettier contain embedded malicious code: installing the package runs an install.js that l…KEVEPSS 4.5%analysed9.3CVE-2025-59374ASUS Live Update client supply chain compromise with embedded malicious codeCertain builds of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modi…KEVEPSS 1.2%analysed8.6CVE-2025-30154reviewdog/action-setup GitHub Action leaks secrets to workflow logsreviewdog/action-setup@v1 was compromised on March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets into G…KEVEPSS 2.4%analysed8.6CVE-2025-30066tj-actions/changed-files GitHub Action leaks secrets via modified tagsThe tj-actions/changed-files GitHub Action was compromised: tags v1 through v45.0.7 were modified on 2025-03-14 and 2025-03-15 to point at commit 0e5…KEVEPSS 72%analysed

Source: NIST National Vulnerability Database (record CVE-2024-4978), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.