Junglewise Threat Intelligence

CVE-2026-50663: Microsoft Age of Empires II: Definitive Edition path traversal

CVE-2026-50663 · Severity: high · CVSS 8.8 · Published 2026-07-14

Vendors: Microsoft.

Executive brief

A security vulnerability exists in the popular strategy game Age of Empires II: Definitive Edition. An attacker could potentially take control of a player's computer or execute malicious software if the player interacts with a specially crafted file or network resource. This poses a risk to personal data and system integrity for users of the game.

Technical details

A relative path traversal vulnerability (CWE-23) exists in Microsoft's Age of Empires II: Definitive Edition. The flaw allows an unauthenticated attacker to bypass directory restrictions and potentially execute arbitrary code on the victim's system. While the attack vector is network-based, it requires user interaction (UI:R), such as a player opening a malicious file or connecting to a compromised game session. The vulnerability is addressed in versions 101.103.46651.0 and later.

Affected products

  • Microsoft Age of Empires II: Definitive Edition Game 1.0.0 to 101.103.46651.0

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD.
  • 2026-07-14: patched: Fix released in version 101.103.46651.0.

References