Impact
A null pointer dereference flaw exists in the GFAC_Sys_x64.sys driver that is part of Little Orbit’s GameFirst Anti-Cheat. The driver dereference causes the operating system to crash and reboot. The result is a local denial of service on the affected machine; the flaw does not provide code execution, privilege escalation, or remote reachability.
Affected Systems
Little Orbit GameFirst Anti-Cheat, specifically the GFAC_Sys_x64.sys driver. Version details are not disclosed, so any release that may be vulnerable until the vendor releases a fix.
Risk and Exploitability
The CVSS score of 5.5 indicates the vulnerability is moderate. The EPSS score of less than 1 percent shows a very low yet nonzero chance of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale exploitation. Based on the description, it is inferred that the attacker must have local access to the machine running the driver and be able to send crafted requests to trigger the crash. Overall risk remains moderate, but patching is recommended to prevent intentional or accidental service disruption.
OpenCVE Enrichment