Embedded malicious code (backdoor) in JAVS Viewer - CVE-2024-4978
Published: May 24, 2024
JAVS Viewer
Justice AV Solutions
Description
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to presence of embedded malicious functionality in the application setup file "Justice AV Solutions Viewer Setup 8.3.7.250-1" downloaded from the official website. A remote attacker to gain unauthorized access to the system.
Note, the vulnerability is being actively exploited in the wild.