Apps & Consumer
Microsoft patches critical bug in Age of Empires II
Microsoft has patched a record number of security bugs, including a flaw in Age of Empires II that could let hackers hijack computers via game invites.
On Tuesday, Microsoft patched a historic record number of security bugs across its product lines. The company links the scale of the cleanup largely to the use of artificial intelligence — by both its internal teams and external researchers — to surface vulnerabilities that might otherwise have gone unnoticed, marking a shift in how software flaws of this scale get found in the first place.
Among the fixes was a critical patch for the remastered version of the 25-year-old strategy game Age of Empires II. According to security researchers, the flaw allowed hackers to take over a victim’s computer by sending a custom malicious game invite. A video posted on X shows how the flaw could be exploited by hackers, offering a public demonstration of an attack path that ran through what looked like an ordinary multiplayer invitation.
According to Rapid7, a US-based cybersecurity provider and research firm, a successful attack would have allowed hackers to place malicious files on the victim’s computer, opening the door for the hacker to achieve the ability to run malicious code on the victim’s machine. In practice, that would have given an attacker effective control over the compromised computer. There is no evidence that the vulnerability was successfully exploited in the wild — the flaw was caught and patched before any confirmed real-world attack, even as the video demonstration showed the mechanics were sound enough to be reproduced.
The Age of Empires II fix was one piece of a broader patch cycle that Microsoft describes as a historic record in scope, spanning its product lines beyond just the gaming title. That breadth underscores how a single company’s software footprint — from productivity tools to decades-old game franchises it still maintains — creates a correspondingly wide set of entry points for attackers to probe.
Why it matters
The episode highlights how legacy software and popular consumer games remain high-value targets for malware distribution, even as AI rapidly scales companies’ ability to find and fix the vulnerabilities that make such attacks possible.