Adobe patched a local privilege escalation vulnerability in Creative Cloud Desktop for macOS that allowed a local attacker to gain root privileges through the product's privileged helper daemon, /Library/PrivilegedHelperTools/com.adobe.acc.installer. The issue, tracked as CVE-2018-4991 and addressed in Adobe Security Bulletin APSB18-12, affected an XPC method that could launch processes as root while relying on insufficient caller validation.
Technical analysis showed the helper's codesign-based trust check was vulnerable to a time-of-check/time-of-use race condition, allowing an attacker to swap a validated binary before execution or abuse trusted Adobe-signed interpreters such as Node.js to run arbitrary code with elevated privileges. Adobe's fix removed the flawed signature-checking logic and tightened the code-signing requirement used to authorize requests, while the researcher warned that similar patterns might exist in other Adobe components.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A public blog post described a local privilege escalation vulnerability in Adobe Creative Cloud Desktop on macOS involving the privileged helper daemon com.adobe.acc.installer. The write-up explained the signature-validation bypass and TOCTOU issues, and included a proof-of-concept showing how an attacker could execute code as root using an Adobe-signed Node.js binary.
Adobe issued Security Bulletin APSB18-12 addressing CVE-2018-4991 in Adobe Creative Cloud Desktop. According to the later technical write-up, the fix removed the buggy codesign checker and tightened the codesign requirement string.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.