Description
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
Published: 2026-07-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap-based buffer overflow in the Bedrock Dedicated Server enables an attacker who can send specially crafted network traffic to execute arbitrary code on the host system. The vulnerability permits full control over the server, allowing malicious payloads to run with the same privileges as the server process. The severity is high, as reflected by the CVSS score of 9.8.

Affected Systems

The affected product is Microsoft Minecraft Bedrock Dedicated Server. Version information was not disclosed in the advisory, so any installation of the server is potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, but the EPSS score of less than 1% suggests the likelihood of exploitation in the wild is very low at this time. The vulnerability is not listed in CISA’s KEV catalog, further indicating limited current exploitation activity. The likely attack vector is an unauthorized remote attacker sending crafted packets to the server; exploitation would require the attacker to have network connectivity to the vulnerable service.

Generated by OpenCVE AI on July 31, 2026 at 07:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft update for Minecraft Bedrock Dedicated Server from the official Microsoft Update Catalog or the server's built-in update mechanism.
  • Disable or restrict network access to the Bedrock Dedicated Server service until a patch is installed.
  • Configure the host firewall to block inbound traffic on the Bedrock Dedicated Server port (default 19132) from untrusted networks and enable network segmentation or VPN to limit exposure.

Generated by OpenCVE AI on July 31, 2026 at 07:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
Title Minecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft minecraft Bedrock Dedicated Server
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:minecraft_bedrock_dedicated_server:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft minecraft Bedrock Dedicated Server
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Minecraft Bedrock Dedicated Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:47.139Z

Reserved: 2026-06-16T14:12:44.283Z

Link: CVE-2026-55010

cve-icon Vulnrichment

Updated: 2026-07-14T19:19:25.566Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow