Mojira Archive
MC-193400

Dll side loading in Minecraft Java

Hello,

When loading Minecraft java version 1.16.1 (already exist for older versions), java try to load a dll from a c:\program%20files%20(x86) instead of c:\program files (x86)

This path error permit to a user without privilege to load a fake dll when any user launch minecraft.

A fake installer can also create this folder structure without starting UAC.

A possibility to exploit this bug is to try to steal credential when user start game.

Fixed

Xavier DANEST

2020-07-03, 03:48 PM

2021-05-12, 02:33 PM

2021-05-12, 02:33 PM

0

1

Plausible

Important

Save Data

1.16.1

21w19a