CVE-2024-12786

HIGH

X1a0He Adobe Downloader <1.3.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. This product is not affiliated with the company Adobe.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.288966
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.288966
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.464685

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-269
Status published
Products (2)
X1a0He/Adobe Downloader 1.3.0
X1a0He/Adobe Downloader 1.3.1
Published Dec 19, 2024
Tracked Since Feb 18, 2026