A vulnerability in the matchmaking servers of Bandai Namco FromSoftware Dark Souls III (through 2022-03-19) allows remote attackers to send arbitrary push requests to clients by abusing the RequestSendMessageToPlayers functionality. The restriction on the number of push messages is enforced only on the client side, which can be bypassed by using a modified client, enabling attackers to send push messages to a large number of machines.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2022-24125 and CVE-2022-24126, which are critical remote code execution vulnerabilities in FromSoftware's Dark Souls III (and related titles) on Windows. The exploit leverages improper bounds checking in the NRSessionSearchResult matchmaking data parser, allowing an attacker to craft a malicious packet that triggers a stack buffer overflow and arbitrary code execution via virtual function table (vftable) manipulation. The repository is structured as a Visual Studio C++ solution with two main components: - **Injector**: A console application (Injector.cpp) that locates the running DarkSoulsIII.exe process and injects a DLL (RCE_POC.dll) into it using standard Windows process injection techniques (OpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThread with LoadLibraryW). - **RCE_POC DLL**: The injected DLL (dllmain.cpp, rce.cpp, rce.h, FdpClient.hpp, DeepPtr.hpp, and Protobuf helpers) contains the exploit logic. Upon injection, it constructs a malicious matchmaking packet using custom Protobuf serialization and sends it to the local player (or other players) via the game's matchmaking system. The exploit payload is a shellcode byte array that is executed as a result of the vulnerability. The exploit is network-based, requiring the target to be online and connected to a vulnerable matchmaking server. The PoC is specific to Dark Souls III up to version 1.15.0, but the vulnerability is present in other FromSoftware titles as well. The README provides extensive technical documentation, including the vulnerability details, exploitation strategy, and affected products. No hardcoded IP addresses or external network endpoints are present; the exploit targets the local game process and leverages the game's own networking to deliver the payload. Overall, this repository demonstrates a sophisticated RCE exploit chain, including process injection, custom packet crafting, and exploitation of a game-specific protocol vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.