« Volver al listado

CVE-2020-8290

Estado: ModificadaAlta (7.8)—

Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-8290",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Backblaze",
          "versions": [
            {
              "status": "affected",
              "version": "Prior to 7.0.0.439"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-27T02:15:14.573",
  "references": [
    {
      "url": "https://github.com/geffner/CVE-2020-8290/blob/master/README.md",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://hackerone.com/reports/818857",
      "tags": [
        "Permissions Required"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://youtu.be/OpC6neWd2aM",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://github.com/geffner/CVE-2020-8290/blob/master/README.md",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hackerone.com/reports/818857",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://youtu.be/OpC6neWd2aM",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary."
    },
    {
      "lang": "es",
      "value": "Backblaze para Windows y Backblaze para macOS versiones anteriores a 7.0.0.439, sufren de una administración de privilegios inadecuada en el asistente \"bztransmit\" debido a la falta de manejo y comprobación de permisos antes de la creación de directorios de actualización de clientes que permiten la escalada local de privilegios por medio del binario de actualización de cliente no autorizado"
    }
  ],
  "lastModified": "2026-06-17T03:26:13.947",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:macos:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA80ABAD-2620-4350-B506-ACCF9B4A18E3",
              "versionEndExcluding": "7.0.0.439"
            },
            {
              "criteria": "cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7051153-3CAD-442F-BD4B-8C780431FBD4",
              "versionEndExcluding": "7.0.0.439"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}