Embedded malicious code (backdoor) in JAVS Viewer - CVE-2024-4978

 

Embedded malicious code (backdoor) in JAVS Viewer - CVE-2024-4978

Published: May 24, 2024


Vulnerability identifier: #VU89806
CSH Severity: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2024-4978
CWE-ID: CWE-506
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
JAVS Viewer
Software vendor:
Justice AV Solutions

Description

The vulnerability allows a remote attacker to gain unauthorized access to the application.

The vulnerability exists due to presence of embedded malicious functionality in the application setup file "Justice AV Solutions Viewer Setup 8.3.7.250-1" downloaded from the official website. A remote attacker to gain unauthorized access to the system.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install the latest version from vendor's website.

External links