Zero-day vulnerability in JAVS Viewer

Embedded malicious code (backdoor)
CVE-2024-4978

Vulnerability details

Advisory: SB2024052429 - Backdoor in Justice AV Solutions Viewer software

Vulnerable component: JAVS Viewer

CVE-ID: CVE-2024-4978

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-506 - Embedded Malicious Code

Description:

The vulnerability allows a remote attacker to gain unauthorized access to the application.

The vulnerability exists due to presence of embedded malicious functionality in the application setup file "Justice AV Solutions Viewer Setup 8.3.7.250-1" downloaded from the official website. A remote attacker to gain unauthorized access to the system.

Note, the vulnerability is being actively exploited in the wild.

External links:

https://x.com/2RunJack2/status/1775052981966377148

https://github.com/advisories/GHSA-wf54-f8v9-v72v

https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/