PT-2025-39202 · Sunshine · Sunshine
Pundhapat
·
Published
2025-09-23
·
Updated
2025-10-08
·
CVE-2025-54081
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sunshine versions prior to 2025.923.33222
Description
Sunshine, a self-hosted game stream host for Moonlight, is affected by an issue where the Windows service
SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory containing spaces, the Service Control Manager (SCM) may incorrectly interpret the path and potentially execute a malicious binary placed earlier in the search string.Recommendations
Update to version 2025.923.33222 or later.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sunshine