AndroGuider | One Stop For The Techy You!Microsoft Fixes Critical Security Flaw in Age of Empires I…
انتشار: 2026/07/16 01:11 UTC
AndroGuider | One Stop For The Techy You!Microsoft Fixes Critical Security Flaw in Age of Empires IIai4chat-files.s3.amazonaws.com/images/ima… TL;DR* Microsoft patched CVE-2026-50663, an 8.8-rated remote code execution flaw in Age of Empires II: Definitive Edition that allows attackers to execute code via malicious game invites.* The vulnerability stems from a relative path traversal weakness (CWE-23) requiring user interaction to exploit, meaning players must accept an invite or open content from an untrusted source.* Users must update the game to version 101.103.46651.0 or higher via Steam or the Microsoft Store; checking Windows Update alone is insufficient to fix this game-specific issue. Critical Flaw Uncovered in Retro ClassicA newly patched security vulnerability in Age of Empires II: Definitive Edition has exposed players to the risk of remote code execution, potentially allowing hackers to seize control of their computers. Microsoft identified the flaw, tracked as CVE-2026-50663, and released a fix on July 14, 2026, just days after the advisory was published by the Microsoft Security Response Center.The vulnerability lies in how the game handles network data, specifically through a relative path traversal error that could let an unauthorized attacker execute malicious code over a network. While the flaw is serious, it is not a "zero-click" attack; it requires a user to take action, such as accepting a game invite or opening content from an untrusted source, to trigger the exploit. The Mechanics of the AttackThe security weakness is classified as CWE-23 (Path Traversal), which allows attackers to manipulate file paths to access or execute files outside the intended directory. Microsoft’s CVSS assessment rates the vulnerability at 8.8 under version 3.1, indicating a "High" severity level, while the older CVSS v2 score hits a maximum 10.0 for "Critical" severity.Key characteristics of the attack include:* Network Reach: An attacker can reach the vulnerable component remotely without physical access to the victim's machine.* Low Complexity: The attack requires no prior privileges and has low complexity, making it accessible to less sophisticated hackers.* High Impact: Successful exploitation can compromise the confidentiality, integrity, and availability of the affected Windows account, potentially leading to full system control.Because the attack relies on user interaction (UI:R), Microsoft emphasizes that the risk is tied to social engineering tactics, such as sending a malicious game invite to a friend who then clicks "accept." Affected Versions and ScopeMicrosoft has confirmed that the vulnerability affects Age of Empires II: Definitive Edition versions from 1.0.0 up to, but not including, 101.103.46651.0. This means any player running a version older than 101.103.46651.0 is at risk and must update immediately.Version 101.103.46651.0 is the first build outside the vulnerable range documented in the CVE record. Players who have not yet updated to this specific build are exposed to the remote code execution risk when joining sessions from untrusted sources. How to Update and Secure Your GameUpdating the game is the only effective mitigation against this flaw. Microsoft explicitly warns that simply checking that Windows Update completed is not sufficient, as the vulnerability resides in the game application itself, not the operating system. The corrective update must be delivered through the specific storefront or game-distribution channel used for the installation. Steps for Steam Users1. Open Steam and navigate to the game’s Properties.2. Check the Updates page to ensure the la[...]