CVE Feed

    Dashboard / CVE / CVE-2024-4978

    CVE-2024-4978

    Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

    Published:May 23, 2024
    Last Modified:Oct 24, 2025
    EPS:May 23, 2024
    EPSS Score:0.23957
    CVSS Score:8.4

    CISA Notification

    Description

    Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

    Required Action:

    Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Jun 19, 2024
    814 days ago
    Alert Date
    May 29, 2024
    835 days ago

    Affected Products

    Vendor
    Javs
    Product
    Javs Viewer
    Vendor
    Javs
    Product
    Viewer

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High