The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.voidtools.com/ |
Configurations
No configuration.
History
04 Nov 2025, 05:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-04 05:16
Updated : 2025-11-04 15:40
NVD link : CVE-2025-12683
Mitre link : CVE-2025-12683
CVE.ORG link : CVE-2025-12683
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
