Impact
A flaw in the GFAC_Sys_x64.sys driver of Little Orbit GameFirst Anti‑Cheat allows a local attacker to send crafted messages through the driver’s Minifilter communication port, culminating in kernel‑mode code execution with SYSTEM privileges. This improper validation of input gives the attacker the ability to run arbitrary code, install malware, or modify system settings. The weakness is captured by CWE‑284 (Improper Access Control) and CWE‑285 (Elevation of Privilege).
Affected Systems
All installations of Little Orbit GameFirst Anti‑Cheat that include the GFAC_Sys_x64.sys driver are exposed; the vendor has not defined specific affected versions, so any release containing this driver is considered vulnerable until a patch is released. The driver operates on Windows platforms where it is installed.
Risk and Exploitability
The CVSS score of 7.8 classifies the defect as high severity, but the EPSS score of less than 1% indicates a very low probability of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. It requires local user access to communicate with the driver’s Minifilter port, with no mentioned remote exploitation pathway. The risk is moderate but the impact of successful exploitation—SYSTEM‑level code execution—is severe.
OpenCVE Enrichment