CVE-2024-4978
Description
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.
Summary dbcve.org
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary that is executed upon installation and is signed with an unexpected Authenticode signature (not the legitimate publisher's certificate). This supply chain compromise allows a remote, privileged attacker to execute unauthorized PowerShell commands on the target system.
Mitigation
Organizations should immediately determine if this specific version (8.3.7.250-1) of Justice AV Solutions Viewer has been deployed, remove any instances found, and conduct forensic analysis to determine if unauthorized PowerShell commands were executed. Implement strict certificate validation for software installers and verify publisher certificates against an expected allowlist.