Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability
Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.
- Vendor
- Justice AV Solutions
- Product
- Viewer
- CVSS
- 8.4
- EPSS (exploit probability)
- 26.9%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this creates a backdoor connection to a malicious C2 server.
Added to CISA’s Known Exploited Vulnerabilities catalog on 2024-05-29. Required action per CISA: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Due date: 2024-06-19.
This is an auto-synced KEV catalog record pending a full 0dayNews write-up — see CISA’s KEV catalog and the NVD record linked above for primary sources.