Researchers disclosed a local privilege escalation flaw in the signed Windows driver bandainamcoonline.sys, which was installed with Mobile Suit Gundam Online via GundamOnline.exe. The driver exposed IOCTL handlers that could disable SMEP and execute attacker-supplied code from user space in kernel mode, allowing any local user to run arbitrary Ring 0 code and gain full system privileges.
Analysis found the vulnerable driver was nearly identical to Capcom’s previously abused capcom.sys, indicating both likely originated from the same anti-cheat code base. The issue was uncovered after sandbox heuristics flagged supervisor-mode execution of user-space memory, and BANDAI NAMCO Online reportedly released a patch within three days that removed the vulnerable driver from the game.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers found the earliest sample of the signed Windows driver bandainamcoonline.sys in November 2015. They assessed it likely predated Capcom's similar vulnerable driver by nearly a year.
BANDAI NAMCO Online responded to Kaspersky's report and released a patch three days later. The update removed the vulnerable driver so it was no longer loaded by the game executable.
After confirming the issue, Kaspersky notified BANDAI NAMCO Online Inc. about the local privilege escalation vulnerability in bandainamcoonline.sys. The notification concerned the driver's ability to let local users execute arbitrary code with kernel privileges.
Kaspersky researchers analyzed GundamOnline.exe and found that its signed driver, bandainamcoonline.sys, exposed IOCTL functionality that disabled SMEP and executed attacker-supplied user-space code in kernel mode. The flaw allowed any local user to gain arbitrary Ring 0 code execution and elevate privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.