Описание
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in bztransmit helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.
Ссылки
- ExploitThird Party Advisory
- Permissions Required
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Permissions Required
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.0.0.439 (исключая)Версия до 7.0.0.439 (исключая)
Одно из
cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:macos:*:*
cpe:2.3:a:backblaze:backblaze:*:*:*:*:*:windows:*:*
EPSS
Процентиль: 29%
0.00108
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-269
CWE-269
Связанные уязвимости
github
больше 3 лет назад
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of privilege via rogue client update binary.
EPSS
Процентиль: 29%
0.00108
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-269
CWE-269