Exploitation Summary
EIP tracks 2 public exploits for CVE-2020-8289. PoCs published by geffner, X1cT34m.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2020-8289, demonstrating remote code execution (RCE) as SYSTEM/root via Backblaze's update mechanism. The exploit leverages SSL certificate validation bypass and file validation flaws to execute arbitrary code.
Description
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.
Exploits (2)
This repository contains a functional proof-of-concept exploit for CVE-2020-8289, demonstrating remote code execution (RCE) as SYSTEM/root via Backblaze's update mechanism. The exploit leverages SSL certificate validation bypass and file validation flaws to execute arbitrary code.
This repository contains a functional proof-of-concept exploit for CVE-2020-8289, demonstrating remote code execution (RCE) as SYSTEM/root via Backblaze's update mechanism. The exploit leverages SSL certificate validation bypass and a weak file validation check to execute arbitrary code.
References (6)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H