CVE-2024-31226

LOW EPSS 12.1%
Published May 16, 20242y ago · Modified Jun 17, 20261w ago
2.9 CVSS 3.1
Low
Find Similar
Published May 16, 2024 2y ago
Last Modified Jun 17, 2026 1w ago

Description

Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a service on Windows may be impacted when terminating the service if an attacked placed a file named `C:\Program.exe`, `C:\Program.bat`, or `C:\Program.cmd` on the user's computer. This attack vector isn't exploitable unless the user has manually loosened ACLs on the system drive. If the user's system locale is not English, then the name of the executable will likely vary. Version 0.23.0 contains a patch for the issue. Some workarounds are available. One may identify and block potentially malicious software executed path interception by using application control tools, like Windows Defender Application Control, AppLocker, or Software Restriction Policies where appropriate. Alternatively, ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory `C:`. Require that all executables be placed in write-protected directories.

CVSS Details

Base Score
2.9
Exploitability
0.3
Impact
2.5
Vector string
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
Attack Vector Local
Attack Complexity High
Privileges Required High
User Interaction Required
Scope Unchanged
Confidentiality Low
Integrity Low
Availability None

Threat Intelligence

EPSS Exploit Probability
12.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-428

Affected Products 1

VendorProductVersionRange
lizardbytesunshine*≥0.17.0  –  <0.23.0

References 3

  • github.com https://github.com/LizardByte/Sunshine/commit/93e622342c4f3e9b34f5f265039b6775b8e33a7a
    Patch
  • github.com https://github.com/LizardByte/Sunshine/pull/2379
    Issue TrackingPatch
  • github.com https://github.com/LizardByte/Sunshine/security/advisories/GHSA-r3rw-mx4q-7vfp
    Vendor Advisory

Remediation

  • github.com https://github.com/LizardByte/Sunshine/commit/93e622342c4f3e9b34f5f265039b6775b8e33a7a
    Patch
  • github.com https://github.com/LizardByte/Sunshine/pull/2379
    Issue TrackingPatch