CVE-2025-10199: A local privilege escalation vulnerability exists in LizardBytes' Sunshine for Windows
Published Sep 9, 2025
·Updated
A local privilege escalation vulnerability exists in Sunshine for Windows (version v2025.122.141614 and likely prior versions) due to an unquoted service path.
Affected Software
3 affected components
LizardBytes Sunshine for Windows<=v2025.122.141614
All of the following
LizardByte Sunshine=2025.122.141614
Microsoft Windows
Event History
Sep 9, 2025
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-10199?
CVE-2025-10199 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2025-10199?
To mitigate CVE-2025-10199, ensure that the service path for Sunshine for Windows is properly quoted.
3
Which versions of Sunshine for Windows are affected by CVE-2025-10199?
CVE-2025-10199 affects Sunshine for Windows version v2025.122.141614 and likely prior versions.
4
What causes CVE-2025-10199 vulnerability?
CVE-2025-10199 is caused by an unquoted service path in the application.
5
Can CVE-2025-10199 lead to unauthorized access?
Yes, CVE-2025-10199 can allow attackers to gain elevated privileges on affected systems.