01 logo

Microsoft Patches 25-Year-Old Age of Empires II Bug That Could Let Hackers Take Over Your PC

A simple game invite could have given attackers full control of your computer. Here's what happened and why you need to update now.

By Mark Lim Published 2 months ago 3 min read

There's something almost nostalgic about firing up Age of Empires II. The clatter of villagers gathering resources, the trumpet sound when you advance to the next age, the satisfying thud of a trebuchet taking down a castle wall. It's a game that's been around for 25 years, a classic that refuses to die. But that long history also means there are corners of its code that nobody has looked at in decades. And sometimes, that's exactly where the dangers hide.

On Tuesday, as part of one of the largest Patch Tuesdays in Microsoft's history, the company quietly fixed a security flaw in the remastered version of Age of Empires II that was genuinely alarming. The vulnerability, tracked as CVE-2026-50663, could have allowed hackers to take over a victim's computer simply by sending them a malicious game invite.

Yes, you read that correctly. A game invite. In a 25-year-old strategy game.


The Attack: How a Game Invite Became a Weapon

The vulnerability was discovered with the help of AI tools that Microsoft and external researchers have been using to uncover hidden flaws in their products. And it's a good thing they did, because this was not a minor issue.

According to security researchers, the exploit worked like this: an attacker would create a custom game lobby and send an invite to a target player. If the victim joined the lobby and accepted the custom content often, automatically, malicious code would be executed on their machine.

Security firm Rapid7 analyzed the flaw and confirmed that a successful attack would allow hackers to place malicious files on the victim's computer, opening the door for them to run any code they wanted. In plain terms, they could take full control of your PC. Your passwords, your personal photos, your banking details, everything stored on that machine would be at risk.

The vulnerability stems from something called a "relative path traversal" weakness, which essentially means the game didn't properly check where files were being saved or executed when processing custom content from other players. A flaw like this can allow an attacker to drop a malicious file in an unexpected location on your hard drive and then trick the system into running it.


The Context: A Record-Breaking Patch Tuesday

This wasn't just any security update. July 2026's Patch Tuesday was historic. Microsoft patched approximately 570 vulnerabilities across its entire product line a number that shattered previous records. By some counts, it was nearly three times larger than the previous month's update, and five to ten times larger than typical monthly patches .

The sheer volume was driven largely by the use of AI-powered scanning tools that helped identify bugs across even the oldest and most obscure components of Microsoft's software. Even MIDI drivers from decades past received updates. And yes, that included a 25-year-old game that many still play today.

Of the 570 vulnerabilities, 59 were rated "critical." The Age of Empires II bug, while given a CVSS score of 8.8 (high severity), was not classified as critical because it required user interaction the victim had to actually join the lobby . But that's cold comfort. In the world of online gaming, clicking "accept" on an invite is second nature.


This Means for Players?

If you're still playing Age of Empires II: Definitive Edition, you need to update the game immediately. The fixed version is 101.103.46651.0. If you're running anything older, you're vulnerable.

On Steam, check the game's properties and make sure the update has been installed. On the Microsoft Store, check your library for pending updates . And here's a crucial detail: this update comes through the storefront, not Windows Update. Installing the latest Windows patches alone isn't enough.

There's no evidence that this bug has been actively exploited in the wild, but that's not a reason to be complacent . Security researchers have warned that targeting gamers is an effective way for hackers to install malware on a large number of machines. Gamers often run powerful PCs with valuable data, and they're used to accepting invites and downloading custom content without thinking twice.

While the vulnerability required a specific set of actions to exploit, it's a stark reminder that even beloved classics the games we trust and have played for decades can harbor dangerous flaws. And as gamers, it's a good practice to be cautious about accepting invites or custom content from strangers, no matter how harmless it might seem.

Stay safe out there. And update your games.

tech news

About the Creator

Mark Lim

Hi I am mark an automotive student and a car, tech and food enthusiast ! Im gonna try and post daily & hope you enjoy what I write and do share my page with people you know. I would gladly appreciate it! Cheers

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed. You could also become a paid subscriber, letting them know you appreciate their work.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by Mark Lim