CVE-2020-8290

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
27/12/2020
Last modified:
31/12/2020

Description

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:macos:*:* 7.0.0.439 (excluding)
cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:windows:*:* 7.0.0.439 (excluding)