Mojira Archive
MCL-10795

Clicking on "View Crash Report" can execute any file

https://youtu.be/tAi777pI1PU

When you write to log outputĀ 

@!@# Game crashed! Crash report saved to: #@!@# C:\Windows\system32\notepad.exe

Minecraft Launcher will parse this and after click "View crash report", it runs an executable file (like calculator, notepad). It can also download a file from Samba server (for example:
IP address\executable file or .hta). Of course, Minecraft Launcher will show "Game crash" only if the exit code is other than 0, so the easiest way from the multiplayer server is spam a lot of items with large NBT and crash outofmemory (Minecraft won't create a new file if there'is a problem in native with OOM). Please block is, for example:

  • checking if a file ends with .txt,
  • grabbing file location only after "---- Minecraft Crash Report ----" in logs,
  • checking if the file starts with "---- Minecraft Crash Report ----"

Fixed

k0l0r3k99

[Mojang] slicedlime

2019-05-01, 03:13 AM

2020-03-16, 12:58 PM

2019-05-14, 05:06 PM

1

4

Confirmed

crash-report, launcher-bug, security

2.1.3674-2.1.3677

2.1.4974-2.1.4976