PT-2022-28287 · Mojang · Minecraft Windows Client

Published

2022-01-21

·

Updated

2022-01-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Minecraft Windows client (affected versions not specified)
Description The issue arises when the Minecraft Windows client sends malformed JSON in form responses, which the json decode() function cannot parse. A workaround, implemented in the InGamePacketHandler::stupid json decode() function, attempts to fix errors in the JSON. However, if this function fails, it throws an InvalidArgumentException that is not caught, leading to a server crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-WJFQ-88Q2-R34J

Affected Products

Minecraft Windows Client