Impact
A relative path traversal flaw in Age of Empires II: Definitive Edition lets an unauthorized attacker provide a path that resolves outside the intended directory and load or overwrite files, enabling the attacker to run arbitrary code on the host. The weakness, labeled CWE‑23, allows a remote attacker to exploit the game’s networking interface to trigger the traversal and execute payloads with the privileges of the game process.
Affected Systems
The vulnerability applies to installations of Microsoft’s Age of Empires II: Definitive Edition Game. The CVE data does not specify the operating system, so any platform on which the game runs is potentially affected until Microsoft releases an update that corrects the path handling routine.
Risk and Exploitability
The CVSS score of 8.8 marks the flaw as high severity, yet the EPSS score of less than 1 % indicates that, as of this analysis, exploitation attempts are expected to be infrequent. The vulnerability is not included in the CISA KEV catalog, and no public exploits are confirmed. The likely attack vector is remote, delivered via crafted in‑game traffic over the network. Those who have not installed Microsoft’s latest security update remain at risk of remote code execution.
OpenCVE Enrichment