Vulnerability Details CVE-2025-54081
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may execute a malicious binary placed earlier in the search string. This issue has been patched in version 2025.923.33222.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 1.3%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2025-54081
-
cpe:2.3:a:lizardbyte:sunshine:0.10.0
-
cpe:2.3:a:lizardbyte:sunshine:0.10.1
-
cpe:2.3:a:lizardbyte:sunshine:0.11.0
-
cpe:2.3:a:lizardbyte:sunshine:0.11.1
-
cpe:2.3:a:lizardbyte:sunshine:0.12.0
-
cpe:2.3:a:lizardbyte:sunshine:0.13.0
-
cpe:2.3:a:lizardbyte:sunshine:0.14.0
-
cpe:2.3:a:lizardbyte:sunshine:0.14.1
-
cpe:2.3:a:lizardbyte:sunshine:0.15.0
-
cpe:2.3:a:lizardbyte:sunshine:0.16.0
-
cpe:2.3:a:lizardbyte:sunshine:0.17.0
-
cpe:2.3:a:lizardbyte:sunshine:0.18.0
-
cpe:2.3:a:lizardbyte:sunshine:0.18.1
-
cpe:2.3:a:lizardbyte:sunshine:0.18.2
-
cpe:2.3:a:lizardbyte:sunshine:0.18.3
-
cpe:2.3:a:lizardbyte:sunshine:0.18.4
-
cpe:2.3:a:lizardbyte:sunshine:0.19.0
-
cpe:2.3:a:lizardbyte:sunshine:0.19.1
-
cpe:2.3:a:lizardbyte:sunshine:0.20.0
-
cpe:2.3:a:lizardbyte:sunshine:0.21.0
-
cpe:2.3:a:lizardbyte:sunshine:0.22.0
-
cpe:2.3:a:lizardbyte:sunshine:0.22.1
-
cpe:2.3:a:lizardbyte:sunshine:0.22.2
-
cpe:2.3:a:lizardbyte:sunshine:0.23.0
-
cpe:2.3:a:lizardbyte:sunshine:0.23.1
-
cpe:2.3:a:lizardbyte:sunshine:2025.118.151840
-
cpe:2.3:a:lizardbyte:sunshine:2025.122.141614
-
cpe:2.3:a:lizardbyte:sunshine:2025.628.4510
-
cpe:2.3:a:lizardbyte:sunshine:2025.828.181854
-
cpe:2.3:a:lizardbyte:sunshine:2025.829.135256
-
cpe:2.3:o:microsoft:windows:-