Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may execute a malicious binary placed earlier in the search string. This issue has been patched in version 2025.923.33222.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lizardbyte
Lizardbyte sunshine Microsoft Microsoft windows |
|
Vendors & Products |
Lizardbyte
Lizardbyte sunshine Microsoft Microsoft windows |
Tue, 23 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 23 Sep 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may execute a malicious binary placed earlier in the search string. This issue has been patched in version 2025.923.33222. | |
Title | SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution | |
Weaknesses | CWE-428 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-23T18:18:39.474Z
Updated: 2025-09-23T19:17:53.733Z
Reserved: 2025-07-16T13:22:18.207Z
Link: CVE-2025-54081

Updated: 2025-09-23T19:15:30.276Z

Status : Awaiting Analysis
Published: 2025-09-23T19:15:39.963
Modified: 2025-09-24T18:11:24.520
Link: CVE-2025-54081

No data.