CVE-2025-12683 Details
Description
The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.
A vulnerability exists in the Everything application, specifically in versions prior to 1.5a, due to the service running as SYSTEM and communicating with the lower-privileged GUI via a named pipe. This named pipe has a NULL DACL, granting full permissions to all users. As a result, a local low-privilege user could potentially exploit this vulnerability for privilege escalation (if combined with other factors) or to cause a denial-of-service.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 4, 2025CISA-ADP
Assessed Nov 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.voidtools.com/ | Gridware | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | Gridware |
Affected Products
| Product | Versions |
|---|---|
| voidtools Everything | < 1.4.1.1029 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Gridware |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | Gridware |
| Nov 4, 2025 | CVE Modified | Gridware |
| Nov 4, 2025 | New CVE Received | Gridware |
Volerion