Executive brief
A security vulnerability exists in the popular strategy game Age of Empires II: Definitive Edition. An attacker could potentially take control of a player's computer or execute malicious software if the player interacts with a specially crafted file or network resource. This poses a risk to personal data and system integrity for users of the game.
Technical details
A relative path traversal vulnerability (CWE-23) exists in Microsoft's Age of Empires II: Definitive Edition. The flaw allows an unauthenticated attacker to bypass directory restrictions and potentially execute arbitrary code on the victim's system. While the attack vector is network-based, it requires user interaction (UI:R), such as a player opening a malicious file or connecting to a compromised game session. The vulnerability is addressed in versions 101.103.46651.0 and later.
Affected products
- Microsoft Age of Empires II: Definitive Edition Game 1.0.0 to 101.103.46651.0
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD.
- 2026-07-14: patched: Fix released in version 101.103.46651.0.