7.8
CVE-2025-10199
- EPSS 0.18%
- Veröffentlicht 09.09.2025 17:30:19
- Zuletzt bearbeitet 03.11.2025 19:15:44
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windows
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lizardbyte ≫ Sunshine Version2025.122.141614
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.074 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-428 Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
https://github.com/LizardByte/Sunshine/security/advisories/GHSA-r3rw-mx4q-7vfp
https://www.kb.cert.org/vuls/id/974249