Description
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A relative path traversal flaw in Age of Empires II: Definitive Edition lets an unauthorized attacker provide a path that resolves outside the intended directory and load or overwrite files, enabling the attacker to run arbitrary code on the host. The weakness, labeled CWE‑23, allows a remote attacker to exploit the game’s networking interface to trigger the traversal and execute payloads with the privileges of the game process.

Affected Systems

The vulnerability applies to installations of Microsoft’s Age of Empires II: Definitive Edition Game. The CVE data does not specify the operating system, so any platform on which the game runs is potentially affected until Microsoft releases an update that corrects the path handling routine.

Risk and Exploitability

The CVSS score of 8.8 marks the flaw as high severity, yet the EPSS score of less than 1 % indicates that, as of this analysis, exploitation attempts are expected to be infrequent. The vulnerability is not included in the CISA KEV catalog, and no public exploits are confirmed. The likely attack vector is remote, delivered via crafted in‑game traffic over the network. Those who have not installed Microsoft’s latest security update remain at risk of remote code execution.

Generated by OpenCVE AI on July 31, 2026 at 09:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update that contains the fix for Age of Empires II: Definitive Edition.
  • Reboot the computer to ensure the patch takes effect and clear any stale game state.
  • Configure the system firewall to block inbound traffic on the ports used by Age of Empires II or limit connections to trusted IP ranges.

Generated by OpenCVE AI on July 31, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft age Of Empires Ii
Vendors & Products Microsoft age Of Empires Ii

Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.
Title Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft age Of Empires Ii
Weaknesses CWE-23
CPEs cpe:2.3:a:microsoft:age_of_empires_II:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft age Of Empires Ii
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Age Of Empires Ii Age Of Empires Ii
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:04.301Z

Reserved: 2026-06-05T14:33:50.831Z

Link: CVE-2026-50663

cve-icon Vulnrichment

Updated: 2026-07-15T13:27:00.149Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:45:04Z

Weaknesses
  • CWE-23

    Relative Path Traversal