CVE detail
CVE-2024-4978 — Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
Published 2024-05-29 · Modified 2024-05-29 · Source kev
HIGH
severity
CVSS-derived band
0.2694
EPSS probability
exploitation probability, 30d
98.0%
EPSS percentile
percentile vs all CVEs
LISTED
CISA KEV
due 2024-06-19
⚠ Actively exploited in the wild — CISA KEV listed 2024-05-29, federal remediation due 2024-06-19.
Description
Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References