Impact
The GFAC_Sys_x64.sys driver in Little Orbit’s GameFirst anti‑cheat contains a Minifilter communication port that does not enforce proper access restrictions. This allows a local attacker who can run code on the machine to connect to the port and invoke privileged driver operations, effectively executing kernel‑mode code and escalating privileges. The flaw represents an access‑control violation identified as CWE‑284.
Affected Systems
All installations of Little Orbit GameFirst anti‑cheat that include the GFAC_Sys_x64.sys driver are affected. No specific version range is provided, so any version currently deployed is potentially vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8 and an EPSS score of less than 1%, indicating a high severity but a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack vector is local; a malicious user who can run code on the target machine can contact the Minifilter port and trigger privileged driver functionality, leading to kernel‑mode privilege escalation.
OpenCVE Enrichment