CVE-2025-10198: LizardBytes Sunshine for Windows contains a DLL search-order hijacking vulnerability
Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10198?
CVE-2025-10198 is considered a high severity vulnerability due to its potential for DLL search-order hijacking.
How do I fix CVE-2025-10198?
To mitigate CVE-2025-10198, ensure that the application is updated to the latest version provided by LizardBytes that addresses this vulnerability.
What is a DLL search-order hijacking vulnerability?
A DLL search-order hijacking vulnerability occurs when an attacker can place a malicious DLL in a user-writable directory that is prioritized by the system over legitimate DLLs.
Can CVE-2025-10198 affect my system if I am not using LizardBytes Sunshine for Windows?
No, CVE-2025-10198 specifically affects only versions of LizardBytes Sunshine for Windows.
What steps should I take if I suspect exploitation of CVE-2025-10198?
If you suspect exploitation of CVE-2025-10198, you should immediately remove any unauthorized DLLs from user-writeable directories and update your software to the latest version.