CVE-2024-12786

CVSS 2.0 Score 6.8 of 10 (medium)

Details

Published Dec 19, 2024
CWE ID 269
CWE ID 266

Summary

CVE-2024-12786 is a critical vulnerability affecting the X1a0He Adobe Downloader up to version 1.3.1 on macOS. The issue lies within the function shouldAcceptNewConnection of the com.x1a0he.macOS.Adobe-Downloader.helper XPC Service. This vulnerability results in improper privilege management, which can be exploited locally. The exploit for this vulnerability has been made public, increasing the risk of attacks. It is important to note that X1a0He Adobe Downloader is not an official Adobe product.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share