CVE-2024-4978

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

Scoring

Severity
HIGH
CVSS base score
8.7
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS probability
26.94%
CISA KEV
Known exploited vulnerability
CWE
CWE-506
Published
2024-05-23
Last modified
2025-10-21

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs