Back to search
CVE-2025-12683
Published: Nov 4, 2025
Modified: Nov 4, 2025
PUBLISHED
Description
The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.
| Vendor | Product | Versions |
|---|---|---|
Voidtools | Everything | affected =<1.4.1.1029 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now