Impact
A heap-based buffer overflow in the Bedrock Dedicated Server enables an attacker who can send specially crafted network traffic to execute arbitrary code on the host system. The vulnerability permits full control over the server, allowing malicious payloads to run with the same privileges as the server process. The severity is high, as reflected by the CVSS score of 9.8.
Affected Systems
The affected product is Microsoft Minecraft Bedrock Dedicated Server. Version information was not disclosed in the advisory, so any installation of the server is potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, but the EPSS score of less than 1% suggests the likelihood of exploitation in the wild is very low at this time. The vulnerability is not listed in CISA’s KEV catalog, further indicating limited current exploitation activity. The likely attack vector is an unauthorized remote attacker sending crafted packets to the server; exploitation would require the attacker to have network connectivity to the vulnerable service.
OpenCVE Enrichment