EXPOSURES › CVE-2024-4978
CVE-2024-4978
HIGH ⌖ ON CISA KEV · EXPLOITEDJustice AV Solutions' Viewer installer shipped a malicious ffmpeg.exe backdoor that connects to a C2 server.
The vendor embedded a malicious version of ffmpeg.exe in their installer that establishes a backdoor connection to a command-and-control server upon execution, creating a direct remote access vector for attackers. This represents a severe supply-chain compromise where the vendor itself distributed a compromised binary, exposing DIB organizations to unauthorized access and potential data exfiltration without requiring external exploitation. Immediate remediation requires vendors to audit their installer binaries for embedded malicious code and DIB organizations to block execution of unverified AV Solutions installers.
Shame score — The vendor knowingly or negligently distributed a binary with embedded malicious code that establishes a direct backdoor connection, representing a catastrophic supply-chain failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.