Minecraft: Java Edition should be patched immediately after severe exploit discovered across web

Minecraft Java Edition still
(Image credit: Mojang)

A far-reaching zero-day security vulnerability has been discovered that could allow for remote code execution by nefarious actors on a server, and which could impact heaps of online applications, including Minecraft: Java Edition, Steam, Twitter, and many more if left unchecked.

The exploit ID'd as CVE-2021-44228, which is marked as 9.8 on the severity scale by Red Hat but is fresh enough that it's still awaiting analysis by NVD. It sits within the widely-used Apache Log4j Java-based logging library, and the danger lies in how it enables a user to run code on a server—potentially taking over complete control without proper access or authority, through the use of log messages.

Best of Minecraft

Minecraf 1.18 key art

(Image credit: Mojang)

Minecraft update: What's new?
Minecraft skins: New looks
Minecraft mods:  Beyond vanilla
Minecraft shaders: Spotlight
Minecraft seeds: Fresh new worlds
Minecraft texture packs: Pixelated
Minecraft servers: Online worlds
Minecraft commands: All cheats

"An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled," the CVE ID description states.

The issue could affect Minecraft: Java Edition, Tencent, Apple, Twitter, Amazon, and many more online service providers. That's because while Java isn't so common for users anymore, it is still widely used in enterprise applications. Fortunately, Valve said that Steam is not impacted by the issue.

"We immediately reviewed our services that use log4j and verified that our network security rules blocked downloading and executing untrusted code," a Valve representative told PC Gamer. "We do not believe there are any risks to Steam associated with this vulnerability."

As for a fix, there are thankfully a few options. The issue reportedly affects log4j versions between 2.0 and 2.14.1. Upgrading to Apache Log4j version 2.15 is the best course of action to mitigate the issue, as outlined on the Apache Log4j security vulnerability page. Although, users of older versions may also be mitigated by setting system property "log4j2.formatMsgNoLookups" to “true” or by removing the JndiLookup class from the classpath. 

If you're running a server using Apache, such as your own Minecraft Java server, you will want to upgrade immediately to the newer version or patch your older version as above to ensure your server is protected. Similarly, Mojang has released a patch to secure user's game clients, and further details can be found here.

The long-term fear is that, while those in the know will now mitigate the potentially dangerous flaw, there will be many more left in the dark who will not and may leave the flaw unpatched for a long period of time.

Many already fear the vulnerability is being exploited already, including CERT NZ. As such, many enterprise and cloud users will likely be rushing to patch out the impact as quickly as possible.

"Due to the ease of exploitation and the breadth of applicability, we suspect ransomware actors to begin leveraging this vulnerability immediately," Security firm Randori says in a blog post on the vulnerability.

Jacob Ridley
Managing Editor, Hardware

Jacob earned his first byline writing for his own tech blog. From there, he graduated to professionally breaking things as hardware writer at PCGamesN, and would go on to run the team as hardware editor. He joined PC Gamer's top staff as senior hardware editor before becoming managing editor of the hardware team, and you'll now find him reporting on the latest developments in the technology and gaming industries and testing the newest PC components.

Read more
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
Steam logo
A web3 free-to-play survival game found to be a front for installing malware on your PC has finally been removed from Steam
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
Minecraft servers - An above view from Mineplex
The 15 best Minecraft servers
Latest in Survival & Crafting
Lost Rift screenshot
After suspending development in 2024, People Can Fly brings Project Victoria back to life as survival-extraction shooter Lost Rift
A man examines the implant in his beefy arm
New Ark DLC gets AI-generated trailer so awful that the original developer's washing its hands of the whole thing, and fans are in uproar: 'This is disgusting and you should be ashamed'
Palworld early access
Palworld's Crossplay Update does far more than let you play with console buddies, adding photo mode, a drafting table and 'dimensional Pal Storage'
Three sheep with big guns in Palworld.
It was 'super popular to hate Palworld' after launch, says community manager: 'A lot of companies might crumble under the threats, under the pressure'
Palworld Ancient Civilization Parts - Grizzbolt with a minigun
'It was a very depressing day': Palworld community manager reveals studio's reaction to Nintendo lawsuit
Ark: Lost Colony teaser still.
Ark 2 is still on: The next Ark expansion 'leads into the events of Ark 2,' says Studio Wildcard
Latest in News
Gabe Newell in a Valve promotional video, on a yacht.
Marketing guy invents the concept of 'Real Steam' to explain why 'magic' games, AKA good games, end up selling: 'Don't tell Valve'
CHINA - 2025/02/11: In this photo illustration, a Roblox logo is seen displayed on the screen of a smartphone. (Photo Illustration by Sheldon Cooper/SOPA Images/LightRocket via Getty Images)
'Humans still surpass machines': Roblox has been using a machine learning voice chat moderation system for a year, but in some cases you just can't beat real people
Lucas Pope accepting the Pioneer Award at GDC 2025
Papers, Please creator Lucas Pope says 'it's a tragedy' his 2013 immigration sim now feels so on-the-nose: 'You want your work to be relevant, but at the same time, wow, I really wish it was not that f***ing relevant'
quake champions classic gordon freeman mod
Gordon Freeman joins a retro pandimensional deathmatch in crossover mod Quake Champions Classic
Natarkveld, a horrific amalgamation of Nata and Arkveld, screeches like a creature in Monster Hunter Wilds.
Monster Hunter Wilds player spits in the face of creation, fuses Nata with Arkveld like they're doing a Full Metal Alchemist villain speedrun
An astronaut with helmet doffed looks up at a giant Sugar 1 gaming handheld, floating in space. The rotatable controllers are extended upward, and look like arms.
Sugar 1 is a shape-shifting handheld with two screens and rotatable controllers that make it look like a legally distinct transformable robot