Vulnerability Description
Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lizardbyte | Sunshine | 2025.122.141614 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://github.com/LizardByte/Sunshine/commit/9db11a906167bd962e57896223d7b97180
- https://github.com/LizardByte/Sunshine/pull/3971Issue Tracking
- https://www.kb.cert.org/vuls/id/974249
FAQ
What is CVE-2025-10198?
CVE-2025-10198 is a vulnerability with a CVSS score of 7.8 (HIGH). Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories.
How severe is CVE-2025-10198?
CVE-2025-10198 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10198?
Check the references section above for vendor advisories and patch information. Affected products include: Lizardbyte Sunshine, Microsoft Windows.