CVE-2023-33245
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published May 30, 2023
Updated: Jan 10, 2025
CWE ID 59
Summary
CVE-2023-33245 is a vulnerability affecting Minecraft versions 1.19 and 1.20 pre-releases up to 7 (Java). This issue enables attackers to craft world data containing symlinks, resulting in arbitrary file overwrites. While the description does not indicate code execution as a direct consequence, the potential for code execution exists due to the file overwrite capability. This vulnerability poses a significant risk to users who download and play affected Minecraft versions, as it can lead to unauthorized access and manipulation of their game data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Minecraft