CVE Database
/

CVE-2020-8290

Back to search

CVE-2020-8290

Published: Dec 27, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

VendorProductVersions

n/a

Backblaze

affected
Prior to 7.0.0.439

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now