CVE-2020-24567
Everything vulnerability analysis and mitigation

Overview

voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 (version 1.4.1.990) contained a privilege escalation vulnerability (CVE-2020-24567) that allowed attackers to exploit DLL hijacking via a Trojan horse urlmon.dll file in the installation directory. The vulnerability was discovered by Cymaera on August 16, 2020, reported to voidtools on August 17, 2020, and patched on August 18, 2020 (Cymaera Article).

Technical details

The vulnerability exists because the Everything service, which runs with NT AUTHORITY\SYSTEM privileges, attempts to load urlmon.dll from its installation directory before loading it from C:\Windows\System32. This DLL loading behavior allows an attacker to place a malicious urlmon.dll in the installation directory to achieve code execution with SYSTEM privileges. The vulnerability has a CVSS v3.1 Base Score of 7.8 (HIGH) with vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability could allow attackers to achieve privilege escalation to SYSTEM level permissions, establish persistence across system reboots, and potentially bypass whitelisting mechanisms since the malicious code would be executed on behalf of a signed service (Cymaera Article).

Mitigation and workarounds

The vulnerability was patched in Everything version 1.4.1.990 released on August 18, 2020. Users should upgrade to this version or later. The fix addresses the security issue with loading urlmon.dll and imm32.dll (Voidtools Forum).

Additional resources


SourceThis report was generated using AI

Related Everything vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-24567HIGH7.8
  • EverythingEverything
  • cpe:2.3:a:voidtools:everything
NoYesAug 21, 2020
CVE-2021-20784MEDIUM6.1
  • EverythingEverything
  • cpe:2.3:a:voidtools:everything
NoYesJul 14, 2021
CVE-2025-12683MEDIUM5.8
  • EverythingEverything
  • cpe:2.3:a:voidtools:everything
NoNoNov 04, 2025
CVE-2023-27704MEDIUM5.5
  • EverythingEverything
  • cpe:2.3:a:voidtools:everything
NoYesApr 12, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management