CVE-2024-4978 is a critical supply chain vulnerability affecting Justice AV Solutions Viewer Setup 8.3.7.250-1, where the installer contains a malicious binary signed with an unexpected authenticode signature. This allows a remote, privileged attacker to execute unauthorized PowerShell commands, leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 8.4 (High) and an EPSS score indicating significant exploitability, this vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog. Despite no public exploit code on Metasploit, Nuclei, or ExploitDB, there is substantial community discussion and media coverage, highlighting its severity and the widespread impact on court systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.3.7.250CPE matchmatch criteria | cpe:2.3:a:javs:javs_viewer:8.3.7.250:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.