Unrated severityNVD Advisory· Published Sep 23, 2025· Updated Sep 23, 2025
SunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution
CVE-2025-54081
Description
Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may execute a malicious binary placed earlier in the search string. This issue has been patched in version 2025.923.33222.
Affected products
1- Range: < 2025.923.33222
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/LizardByte/Sunshine/commit/f22b00d6981f756d3531fba0028723d4a5065824mitrex_refsource_MISC
- github.com/LizardByte/Sunshine/releases/tag/v2025.923.33222mitrex_refsource_MISC
- github.com/LizardByte/Sunshine/security/advisories/GHSA-6p7j-5v8v-w45hmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.