DLL Search-Order Hijacking Vulnerability in Sunshine for Windows
CVE-2025-10198

Currently unrated

Key Information:

Vendor

Lizardbyte

Vendor
CVE Published:
9 September 2025

What is CVE-2025-10198?

Sunshine for Windows version v2025.122.141614 is susceptible to a DLL search-order hijacking vulnerability. This flaw enables attackers to exploit user-writeable PATH directories, potentially allowing the insertion of malicious DLLs. Such a vulnerability could lead to unauthorized code execution, offering attackers an opportunity to compromise affected systems. Users of Sunshine for Windows are urged to review their configurations and stay updated to mitigate risks associated with this issue.

Affected Version(s)

Sunshine for Windows v2025.122.141614

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10198 : DLL Search-Order Hijacking Vulnerability in Sunshine for Windows