CVE-2025-54081
Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may execute a malicious binary placed earlier in the search string. This issue has been patched in version 2025.923.33222.
- CVSS 3.1
- 7.0 HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-428
- Affected
- lizardbyte/sunshine
- Source
- security-advisories@github.com
References
- https://github.com/LizardByte/Sunshine/commit/f22b00d6981f756d3531fba0028723d4a5065824Patch
- https://github.com/LizardByte/Sunshine/releases/tag/v2025.923.33222Release Notes
- https://github.com/LizardByte/Sunshine/security/advisories/GHSA-6p7j-5v8v-w45hExploit, Vendor Advisory
- https://github.com/LizardByte/Sunshine/security/advisories/GHSA-6p7j-5v8v-w45hExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.