Back to Database
Status published
Unknown
CVE-2025-10199
A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windows
Vulnerability Description
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10199
Credits & Attribution
No credits recorded in the NVD database.
More from LizardByte
View All →CVE-2025-54081
SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution
Medium
6.7
CVE-2025-53096
Sunshine clickjacking in the UI leads to unauthorized actions being performed
Medium
5.4
CVE-2025-53095
Sunshine application-wide CSRF in the UI leads to command injection as Administrator
Critical
9.7
CVE-2025-10198
LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerability
Unknown
0
CVE-2024-51738
Sunshine improperly enforces pairing protocol request order
High
7.7
Affected Vendor
LizardByte
View all reports →Affected Software
Sunshine for Windows
Vulnerable Versions:
v2025.122.141614
Timeline
Official Publish:
September 9th, 2025
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.