VYPR
High severity7.8NVD Advisory· Published Dec 27, 2020· Updated Jun 17, 2026

CVE-2020-8290

CVE-2020-8290

Description

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in bztransmit helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:macos:*:*+ 2 more
    • cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:macos:*:*range: <7.0.0.439
    • cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:windows:*:*range: <7.0.0.439
    • (no CPE)range: <7.0.0.439
  • Backblaze/Backblaze for Windowsdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.