DLL Search-Order Hijacking Vulnerability in Sunshine for Windows
CVE-2025-10198

7.8HIGH

Key Information:

Vendor

Lizardbyte

Vendor
CVE Published:
9 September 2025

What is CVE-2025-10198?

Sunshine for Windows version v2025.122.141614 is susceptible to a DLL search-order hijacking vulnerability. This flaw enables attackers to exploit user-writeable PATH directories, potentially allowing the insertion of malicious DLLs. Such a vulnerability could lead to unauthorized code execution, offering attackers an opportunity to compromise affected systems. Users of Sunshine for Windows are urged to review their configurations and stay updated to mitigate risks associated with this issue.

Affected Version(s)

Sunshine for Windows v2025.122.141614

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.