Sunshine Game Stream Host Pairing Protocol Vulnerability Allowing MITM Attack and Denial-of-Service
Vulnerability
A vulnerability in Sunshine, a self-hosted game stream host for Moonlight, has been identified in versions through 0.23.1. The issue arises because the pairing protocol does not properly validate the order of requests, leaving it susceptible to a man-in-the-middle (MITM) attack. This flaw could enable an unauthenticated attacker to hijack a legitimate pairing attempt and pair a client maliciously. Additionally, this vulnerability can be exploited by a remote attacker to crash the Sunshine application.
Impact
Exploitation of this vulnerability allows an unauthenticated attacker to perform a MITM attack, hijacking a legitimate client's pairing process with Sunshine. This could result in a malicious client being paired instead, gaining the same access as a legitimate client. Furthermore, the vulnerability can be exploited to intentionally disrupt the pairing process, causing the Sunshine application to crash.
Reproduction
To reproduce this vulnerability, initiate a pairing process between a client and the Sunshine server. An attacker must intercept and modify the pairing requests to exploit the vulnerability. This can be done by observing the request order and introducing forged data, such as a malicious certificate, to replace the legitimate one. The Sunshine application will crash if the pairing process is disrupted by intentionally sending requests out of order.
Remediation
Users can upgrade to Sunshine version 2025.118.151840 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
