Executive brief
Little Orbit GamersFirst Anti-Cheat (GFAC) is a security component bundled with various video games to prevent cheating. A vulnerability in its kernel driver allows a standard user on a computer to intentionally crash the entire operating system, leading to a 'Blue Screen of Death' (BSOD). This can result in data loss for active applications and significant disruption to business or personal operations on the affected machine.
Technical details
A NULL pointer dereference exists in the Little Orbit GamersFirst Anti-Cheat (GFAC) kernel-mode driver, GFAC_Sys_x64.sys, specifically within its initialization and request-handling logic. The vulnerability is reachable via a minifilter communication port that lacks restrictive security descriptors (related to CVE-2026-12167), allowing unprivileged local users to send crafted requests. When the driver processes these requests, it attempts to read or write through a NULL address, triggering a kernel panic (Bug Check) and immediate system crash. As of the advisory date, no vendor patch is available, and the vulnerability is tracked alongside more severe arbitrary kernel memory write issues (CVE-2026-12168).
Affected products
- Little Orbit GamersFirst Anti-Cheat (GFAC) All versions including and prior to 2025-07-07
Timeline
- 2026-04-01: other: Vendor contacted by researcher
- 2026-04-20: other: Case submitted to CERT/CC for coordination
- 2026-07-02: disclosed: Public advisory released by researcher and CERT/CC