VORANT. Threat Intelligence Sign in Get the full feed

GFAC anti-cheat driver has privilege escalation flaws

routine vulnerability

GamersFirst Anti-Cheat driver contains multiple vulnerabilities allowing local attackers to escalate to SYSTEM or crash systems via insecure minifilter port handling.

The GamersFirst Anti-Cheat (GFAC) kernel driver GFAC_Sys_x64.sys, developed by Little Orbit, contains three critical vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. The driver exposes privileged functionality to user-mode applications without proper access controls or input validation.

CVE-2026-12168 represents the most severe flaw: an arbitrary kernel memory write vulnerability allowing attackers to modify sensitive operating system structures like process security tokens, achieving SYSTEM-level privilege escalation. CVE-2026-12167 enables low-privileged users to connect to the driver's communication port due to insufficiently restrictive security descriptors, exposing functions intended only for trusted processes. CVE-2026-12166 is a NULL pointer dereference leading to system crashes.

CERT/CC was unable to reach the vendor for coordination. Users are advised to restrict local access, monitor for unauthorized driver interactions, and disable or remove games utilizing GFAC until patches are available. The vulnerabilities were discovered by Lucian Alexandru Necula.

Mentioned in this report

Vulnerabilities CVE-2026-12166CVE-2026-12167CVE-2026-12168

Source reporting: https://kb.cert.org/vuls/id/639124

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free