Executive brief
A critical vulnerability has been identified in the Minecraft Bedrock Dedicated Server software, which is used to host multiplayer game sessions. This flaw allows an unauthorized person to remotely take control of the server over the internet without needing any login credentials. An exploit could lead to a total shutdown of the gaming service, theft of server data, or the use of the server as a foothold for further attacks on the hosting network.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Minecraft Bedrock Dedicated Server. The vulnerability is reachable over the network and requires no prior authentication or user interaction. By sending specially crafted packets to the server's network port, an attacker can trigger memory corruption to achieve remote code execution (RCE) in the context of the server process. This poses a high risk to confidentiality, integrity, and availability. Microsoft has released an advisory via the MSRC Update Guide, and administrators should update their server instances to the latest version immediately.
Affected products
- Microsoft Minecraft Bedrock Dedicated Server All versions prior to patch
Timeline
- 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD
- 2026-07-14: advisory: Microsoft Security Response Center advisory released