CVE-2023-33245

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published May 30, 2023
Updated: Jan 10, 2025
CWE ID 59

Summary

CVE-2023-33245 is a vulnerability affecting Minecraft versions 1.19 and 1.20 pre-releases up to 7 (Java). This issue enables attackers to craft world data containing symlinks, resulting in arbitrary file overwrites. While the description does not indicate code execution as a direct consequence, the potential for code execution exists due to the file overwrite capability. This vulnerability poses a significant risk to users who download and play affected Minecraft versions, as it can lead to unauthorized access and manipulation of their game data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share