CVE-2025-54081
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-428
Ruta de búsqueda o elemento sin entrecomillar
Fecha de publicación:
23/09/2025
Última modificación:
24/09/2025
Descripción
*** Pendiente de traducción *** Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.923.33222, the Windows service SunshineService is installed with an unquoted executable path. If Sunshine is installed in a directory whose name includes a space, the Service Control Manager (SCM) interprets the path incrementally and may execute a malicious binary placed earlier in the search string. This issue has been patched in version 2025.923.33222.
Impacto
Puntuación base 3.x
6.70
Gravedad 3.x
MEDIA
Referencias a soluciones, herramientas e información
- https://github.com/LizardByte/Sunshine/commit/f22b00d6981f756d3531fba0028723d4a5065824
- https://github.com/LizardByte/Sunshine/releases/tag/v2025.923.33222
- https://github.com/LizardByte/Sunshine/security/advisories/GHSA-6p7j-5v8v-w45h
- https://github.com/LizardByte/Sunshine/security/advisories/GHSA-6p7j-5v8v-w45h