CVE-2024-43395 HIGH

CVE-2024-43395: CraftOS-PC 2's improperly sanitizied paths cause filesystem escape (Windows)

Vendor Mcjack123
Product craftos2
Weakness CWE-22 · Path traversal
Published August 16, 2024
Last update August 19, 2024

CVSS base score

8.2/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

CraftOS-PC 2 is a rewrite of the desktop port of CraftOS from the popular Minecraft mod ComputerCraft using C++ and a modified version of PUC Lua, as well as SDL for drawing. Prior to version 2.8.3, users of CraftOS-PC 2 on Windows can escape the computer folder and access files anywhere without permission or notice by obfuscating `..`s to bypass the internal check preventing parent directory traversal. Version 2.8.3 contains a patch for this issue.

Key dates

02Disclosure timeline

August 16, 2024 CVE published
August 19, 2024 Record updated