CVE-2024-4978
KEV PoC nicheEmbedded Malicious Code (Backdoored ffmpeg) in Justice AV Solutions Viewer Installer
CISA: Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
The Justice AV Solutions (JAVS) Viewer installer shipped with a trojanized copy of ffmpeg.exe, renamed fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4), classified as CWE-506 embedded malicious code — a supply-chain style compromise rather than a code flaw. The malicious code is triggered when the backdoored fffmpeg.exe binary is run after installing the tampered JAVS Viewer package, at which point it opens a backdoor connection to a malicious command-and-control (C2) server. An attacker gains an outbound channel from the victim machine, enabling potential remote access and follow-on activity such as lateral movement or ransomware staging. Organizations that downloaded and installed the affected JAVS Viewer installer — typically courts and justice agencies using JAVS courtroom audio/video software — are affected. The flaw was added to the CISA Known Exploited Vulnerability catalog on 2024-05-29, indicating known in-the-wild exploitation, and EPSS assigns it a 26.9% probability of exploitation in the next 30 days (98th percentile).
What to do: Follow the vendor's instructions as required by CISA KEV: uninstall the JAVS Viewer, remove or quarantine any fffmpeg.exe on systems (verify against the published SHA256), and reinstall the Viewer only from a freshly downloaded, verified-clean installer from JAVS. Check endpoint logs for outbound connections to unknown C2 servers and hunt for any fffmpeg.exe processes, and treat any machine where the tampered installer ran as potentially compromised until reviewed.
| Justice AV Solutions JAVS Viewer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.
- Affected
- Justice AV Solutions Viewer
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- javs
- Products
- javs viewer
- Weakness
- CWE-506
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X