Impact
A local user can exploit the Backblaze Client for Windows by creating a symbolic link from the client’s backup folder to critical Windows system files. Because the client performs insufficient validation of link targets, the link can be resolved in a way that overwrites or bypasses operating‑system security controls. The result is a non‑bootable machine once the backup runs, effectively denying recovery or normal operation for any user on the affected system.
Affected Systems
Backblaze Backblaze Client for Windows. All installations that use the default backup folder are potentially affected; the CVE report does not specify an affected product version.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate severity. The EPSS score is listed as <1%, showing a very low probability of opportunistic exploitation, and the vulnerability is not in CISA’s KEV catalog. Exploitation requires the attacker to gain administrator‑level access or perform an administrative operation that removes Windows security controls. With those capabilities the attacker can create the malicious link and then trigger a backup, resulting in a local denial of service by rendering the system unable to boot.
OpenCVE Enrichment