GFAC anti-cheat driver has privilege escalation flaws
GamersFirst Anti-Cheat driver contains multiple vulnerabilities allowing local attackers to escalate to SYSTEM or crash systems via insecure minifilter port handling.
The GamersFirst Anti-Cheat (GFAC) kernel driver GFAC_Sys_x64.sys, developed by Little Orbit, contains three critical vulnerabilities stemming from insecure handling of user-controlled input through a minifilter communication port. The driver exposes privileged functionality to user-mode applications without proper access controls or input validation.
CVE-2026-12168 represents the most severe flaw: an arbitrary kernel memory write vulnerability allowing attackers to modify sensitive operating system structures like process security tokens, achieving SYSTEM-level privilege escalation. CVE-2026-12167 enables low-privileged users to connect to the driver's communication port due to insufficiently restrictive security descriptors, exposing functions intended only for trusted processes. CVE-2026-12166 is a NULL pointer dereference leading to system crashes.
CERT/CC was unable to reach the vendor for coordination. Users are advised to restrict local access, monitor for unauthorized driver interactions, and disable or remove games utilizing GFAC until patches are available. The vulnerabilities were discovered by Lucian Alexandru Necula.
Mentioned in this report
Source reporting: https://kb.cert.org/vuls/id/639124
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free