4.6
CVSSv2

CVE-2020-8290

Published: 27/12/2020 Updated: 31/12/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 410
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Backblaze for Windows and Backblaze for macOS prior to 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

backblaze backblaze

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: [FD] CVE-2020-8152 – Elevation of Privilege in Backblaze <!--X-Subject-Header-End--> <!--X-Head-of-Message--> ...

Github Repositories

CVE-2020-8290 – Elevation of Privilege in Backblaze

CVE-2020-8290 – Elevation of Privilege in Backblaze Summary Name: Elevation of Privilege in Backblaze CVE: CVE-2020-8290 Discoverer: Jason Geffner Vendor: Backblaze Product: Backblaze for Windows and Backblaze for macOS Risk: High Discovery Date: 2020-03-13 Publication Data: 2020-09-09 Fixed Version: 700439 Introduction Per Wikipedia, Backblaze is "an online back

CVE-2020-8290 – Elevation of Privilege in Backblaze

CVE-2020-8290 – Elevation of Privilege in Backblaze Summary Name: Elevation of Privilege in Backblaze CVE: CVE-2020-8290 Discoverer: Jason Geffner Vendor: Backblaze Product: Backblaze for Windows and Backblaze for macOS Risk: High Discovery Date: 2020-03-13 Publication Data: 2020-09-09 Fixed Version: 700439 Introduction Per Wikipedia, Backblaze is "an online back