Executive brief
Little Orbit GamersFirst Anti-Cheat (GFAC) is a security component bundled with various video games to prevent cheating. A vulnerability in its system driver allows any user logged into a computer to access sensitive internal functions that should be restricted to the software itself. This flaw can be used by an attacker to bypass security controls and potentially gain full control over the operating system.
Technical details
The kernel-mode driver GFAC_Sys_x64.sys exposes a Minifilter communication port to user-mode applications but fails to enforce a restrictive security descriptor. This improper access control (CWE-284) allows low-privileged, non-administrative local users to establish a connection to the port. Once connected, an attacker can reach privileged driver functionality intended only for trusted processes. This vulnerability serves as a primary enabler for more severe exploits, such as arbitrary kernel memory writes (CVE-2026-12168) or denial-of-service attacks (CVE-2026-12166), by significantly widening the driver's attack surface.
Affected products
- Little Orbit GamersFirst Anti-Cheat (GFAC) Driver <= 2025-07-07
Timeline
- 2026-04-01: other: Vendor first contacted by researcher
- 2026-04-20: other: Case submitted to CERT/CC
- 2026-07-02: disclosed: Public advisory published by researcher and CERT/CC