Vulnerabilities
1 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-4978 | Embedded Malicious Code (Backdoored ffmpeg) in Justice AV Solutions Viewer Installer The Justice AV Solutions (JAVS) Viewer installer shipped with a trojanized copy of ffmpeg.exe, renamed fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4), classified as CWE-506 embedded malicious code — a supply-chain style compromise rather than a code flaw. The malicious code is triggered when the backdoored fffmpeg.exe binary is run after installing the tampered JAVS Viewer package, at which point it opens a backdoor connection to a malicious command-and-control (C2) server. An attacker gains an outbound channel from the victim machine, enabling potential remote access and follow-on activity such as lateral movement or ransomware staging. Organizations that downloaded and installed the affected JAVS Viewer installer — typically courts and justice agencies using JAVS courtroom audio/video software — are affected. The flaw was added to the CISA Known Exploited Vulnerability catalog on 2024-05-29, indicating known in-the-wild exploitation, and EPSS assigns it a 26.9% probability of exploitation in the next 30 days (98th percentile). Do: Follow the vendor's instructions as required by CISA KEV: uninstall the JAVS Viewer, remove or quarantine any fffmpeg.exe on systems (verify against the published SHA256), and reinstall the Viewer only from a freshly downloaded, verified-clean installer from JAVS. Check endpoint logs for outbound connections to unknown C2 servers and hunt for any fffmpeg.exe processes, and treat any machine where the tampered installer ran as potentially compromised until reviewed. | 8.7 | 27% | KEV PoC |
| nicheunknown, likely on the order of thousands of installations (specialized courtroom AV software) |