Vulnerability Description
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lizardbyte | Sunshine | 2025.122.141614 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://github.com/LizardByte/Sunshine/security/advisories/GHSA-r3rw-mx4q-7vfpNot Applicable
- https://www.kb.cert.org/vuls/id/974249
FAQ
What is CVE-2025-10199?
CVE-2025-10199 is a vulnerability with a CVSS score of 7.8 (HIGH). A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
How severe is CVE-2025-10199?
CVE-2025-10199 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10199?
Check the references section above for vendor advisories and patch information. Affected products include: Lizardbyte Sunshine, Microsoft Windows.