Fromsoftware's vulnerability footprint is narrowly scoped to its gaming titles, with the documented signal centered on Dark Souls III and characterized by memory-safety issues including out-of-bounds writes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fromsoftware over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24126CRITICAL A buffer overflow in the NRSessionSearchResult parser in Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allows remote attackers to execute arbitrary code via matchmaki | Mar 20, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-34170CRITICAL Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code. | Jun 15, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-24125HIGH The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push requests to clients via a RequestSendMessageToP | Mar 20, 2022 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fromsoftware.
Media articles that mention a CVE ID that affects a product developed by Fromsoftware — matched by CVE ID, not by vendor name.