CVE Database
/

CVE-2025-12683

Back to search

CVE-2025-12683

Published: Nov 4, 2025

Modified: Nov 4, 2025

PUBLISHED

Description

The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.

VendorProductVersions

Voidtools

Everything

affected
=<1.4.1.1029

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now