CVE-2020-8290 - CVE House
Back to Database
Status published High CVE-2020-8290

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer...

Vulnerability Description

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8290

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Backblaze
Vulnerable Versions:
Prior to 7.0.0.439

Timeline

Official Publish: December 27th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)