ZeroHour

CVE-2020-8290

PoC ×2
CVSS 3.1
7.8 high
EPSS
<1%p46
Published
()
Modified
Description

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

Vendors
backblaze
Products
backblaze
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.