Skip to content
COOEY

EXPOSURES › CVE-2024-4978

CVE-2024-4978

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-4978 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 95/100 exploited-in-wildsupply-chainransomwaredefault-creds

Justice AV Solutions' Viewer installer shipped a malicious ffmpeg.exe backdoor that connects to a C2 server.

The vendor embedded a malicious version of ffmpeg.exe in their installer that establishes a backdoor connection to a command-and-control server upon execution, creating a direct remote access vector for attackers. This represents a severe supply-chain compromise where the vendor itself distributed a compromised binary, exposing DIB organizations to unauthorized access and potential data exfiltration without requiring external exploitation. Immediate remediation requires vendors to audit their installer binaries for embedded malicious code and DIB organizations to block execution of unverified AV Solutions installers.

Shame score — The vendor knowingly or negligently distributed a binary with embedded malicious code that establishes a direct backdoor connection, representing a catastrophic supply-chain failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.