Description

The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.

INFO

Published Date :

2025-11-04T04:23:02.884Z

Last Modified :

2025-11-04T20:50:21.977Z

Source :

Gridware
AFFECTED PRODUCTS

The following products are affected by CVE-2025-12683 vulnerability.

Vendors Products
Voidtools
  • Everything
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-12683.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability