Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6v3-xvp5-5g2q

Опубликовано: 04 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.3

Описание

The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.

The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.

EPSS

Процентиль: 4%
0.00019
Низкий

7.3 High

CVSS4

Дефекты

CWE-269

Связанные уязвимости

nvd
3 месяца назад

The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service Denial Of Service or Privilege escalation(only if chained with other elements) for a local low privilege user.

EPSS

Процентиль: 4%
0.00019
Низкий

7.3 High

CVSS4

Дефекты

CWE-269