High severity7.8NVD Advisory· Published Dec 27, 2020· Updated Jun 17, 2026
CVE-2020-8290
CVE-2020-8290
Description
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in bztransmit helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Backblaze/Backblaze for Windowsdescription
Patches
Vulnerability mechanics
References
3- github.com/geffner/CVE-2020-8290/blob/master/README.mdnvdExploitThird Party Advisory
- youtu.be/OpC6neWd2aMnvdExploitThird Party Advisory
- hackerone.com/reports/818857nvdPermissions Required
News mentions
0No linked articles in our index yet.