A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2024-4978

CVE-2024-4978: Javs Javs Viewer RCE Vulnerability

CVE-2024-4978 is a remote code execution vulnerability in Javs Javs Viewer 8.3.7.250-1 that allows privileged attackers to execute unauthorized PowerShell commands. This article covers technical details, affected versions, and mitigation.

Updated: January 22, 2026

CVE-2024-4978 Overview

CVE-2024-4978 is a critical supply chain vulnerability affecting Justice AV Solutions (JAVS) Viewer Setup version 8.3.7.250-1. The installer contains a malicious binary that is signed with an unexpected authenticode signature, enabling remote threat actors with privileged access to execute unauthorized PowerShell commands on affected systems. This represents a sophisticated supply chain compromise where legitimate software distribution channels were weaponized to deliver malicious payloads.

Critical Impact

This vulnerability is actively exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Organizations using JAVS Viewer in courtrooms and legal environments are at significant risk of unauthorized remote code execution.

Affected Products

  • Justice AV Solutions (JAVS) Viewer version 8.3.7.250-1
  • JAVS Viewer installer packages distributed during the compromise period
  • Systems that installed the backdoored JAVS Viewer software

Discovery Timeline

  • May 23, 2024 - CVE-2024-4978 published to NVD
  • October 24, 2025 - Last updated in NVD database

Technical Details for CVE-2024-4978

Vulnerability Analysis

This vulnerability represents a supply chain attack where the legitimate JAVS Viewer installer was compromised to include embedded malicious code (CWE-506: Embedded Malicious Code). The attack is particularly concerning because the malicious binary was signed with an authenticode signature, which would typically be trusted by Windows systems and security software. The malicious code enables execution of arbitrary PowerShell commands, providing attackers with a powerful foothold for further exploitation.

The attack requires network access and privileged authentication, combined with user interaction to execute the installer. However, given that JAVS Viewer is commonly deployed in courtrooms and legal proceedings environments, the potential for sensitive data exposure and system compromise is significant. Once the backdoored installer is executed, threat actors can remotely execute PowerShell commands, enabling data exfiltration, lateral movement, and persistent access.

Root Cause

The root cause of CVE-2024-4978 is the inclusion of embedded malicious code within the JAVS Viewer installer package. The malicious binary was inserted into the software supply chain and signed with an authenticode certificate to appear legitimate. This represents a compromise of the software build or distribution infrastructure, allowing attackers to inject malicious functionality into otherwise trusted software.

Attack Vector

The attack is delivered via network-accessible distribution channels. The exploitation flow involves:

  1. Distribution: The backdoored installer is downloaded from compromised distribution points
  2. Execution: A user with administrative privileges executes the malicious installer
  3. Payload Activation: The embedded malicious code establishes communication with attacker infrastructure
  4. Command Execution: Remote threat actors execute unauthorized PowerShell commands on the compromised system
  5. Persistence: The malware establishes persistence mechanisms for continued access

The attack leverages the trust placed in signed software installers, bypassing initial security controls that rely on code signing verification.

Detection Methods for CVE-2024-4978

Indicators of Compromise

  • Presence of JAVS Viewer version 8.3.7.250-1 installed on systems
  • Unexpected PowerShell command execution originating from JAVS Viewer processes
  • Network connections to unusual command-and-control infrastructure from JAVS-related processes
  • Authenticode signatures on JAVS binaries that differ from expected vendor certificates

Detection Strategies

  • Monitor for PowerShell execution spawned by JAVS Viewer processes or child processes
  • Implement file integrity monitoring on installed JAVS Viewer components
  • Verify authenticode signatures against known-good JAVS signing certificates
  • Review installation logs for evidence of JAVS Viewer 8.3.7.250-1 deployment
  • Deploy behavioral detection for supply chain attack patterns including signed-but-malicious executables

Monitoring Recommendations

  • Enable PowerShell script block logging and module logging across all endpoints
  • Implement network monitoring for suspicious outbound connections from courtroom and legal environment systems
  • Configure SIEM alerts for JAVS Viewer process anomalies
  • Monitor for lateral movement patterns following JAVS Viewer installation events

How to Mitigate CVE-2024-4978

Immediate Actions Required

  • Immediately isolate any systems running JAVS Viewer version 8.3.7.250-1
  • Conduct forensic analysis on affected systems to determine scope of compromise
  • Re-image affected systems from known-clean backups after forensic preservation
  • Review network logs for evidence of command-and-control communications
  • Update to a clean, verified version of JAVS Viewer from the JAVS Downloads Page

Patch Information

Organizations should obtain a verified clean version of JAVS Viewer directly from Justice AV Solutions. Before installation, verify the authenticode signature matches the legitimate JAVS signing certificate. Given this is a supply chain compromise, it is critical to confirm the integrity of any downloaded installer before deployment. Consult the Rapid7 Analysis on CVE-2024-4978 for detailed technical information about the compromise.

This vulnerability is tracked in the CISA Known Exploited Vulnerabilities Catalog, and federal agencies are required to remediate according to CISA timelines.

Workarounds

  • Block execution of JAVS Viewer 8.3.7.250-1 via application control policies
  • Implement network segmentation to isolate courtroom AV systems from critical infrastructure
  • Deploy endpoint detection and response (EDR) solutions to monitor for post-exploitation activity
  • Enable PowerShell Constrained Language Mode on systems where JAVS Viewer is deployed
  • Implement strict application whitelisting to prevent execution of unauthorized PowerShell commands

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeRCE

  • Vendor/TechJavs Viewer

  • SeverityHIGH

  • CVSS Score8.7

  • EPSS Probability14.15%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityHigh
  • AvailabilityHigh
  • CISA KEV Information
  • In CISA KEVYes
  • CWE References
  • CWE-506

  • NVD-CWE-Other
  • Technical References
  • Twitter Status Update

  • JAVS Downloads Page

  • Rapid7 Analysis on CVE-2024-4978

  • CISA Known Exploited Vulnerabilities
  • Latest CVEs
  • CVE-2024-8261: Prolizyazilim OBS Auth Bypass Vulnerability

  • CVE-2024-13068: LimonDesk Auth Bypass Vulnerability

  • CVE-2025-53679: Fortinet FortiSandbox RCE Vulnerability

  • CVE-2026-9446: Simple POS Inventory System SQLi Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English