Description
A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via crafted requests that trigger a system crash.
Published: 2026-07-02
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference flaw exists in the GFAC_Sys_x64.sys driver that is part of Little Orbit’s GameFirst Anti-Cheat. The driver dereference causes the operating system to crash and reboot. The result is a local denial of service on the affected machine; the flaw does not provide code execution, privilege escalation, or remote reachability.

Affected Systems

Little Orbit GameFirst Anti-Cheat, specifically the GFAC_Sys_x64.sys driver. Version details are not disclosed, so any release that may be vulnerable until the vendor releases a fix.

Risk and Exploitability

The CVSS score of 5.5 indicates the vulnerability is moderate. The EPSS score of less than 1 percent shows a very low yet nonzero chance of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale exploitation. Based on the description, it is inferred that the attacker must have local access to the machine running the driver and be able to send crafted requests to trigger the crash. Overall risk remains moderate, but patching is recommended to prevent intentional or accidental service disruption.

Generated by OpenCVE AI on July 17, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor’s latest patch or update for GameFirst Anti‑Cheat that fixes the GFAC_Sys_x64.sys null pointer dereference.
  • If a patch is not yet available, uninstall or disable the GFAC_Sys_x64.sys driver to eliminate the crash vector.
  • Restrict local access and privilege for users who can load or interact with GameFirst drivers, ensuring only administrators can package or deliver crafted input requests.

Generated by OpenCVE AI on July 17, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Mon, 13 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 08 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Little Orbit
Little Orbit gamefirst Anti-cheat
Vendors & Products Little Orbit
Little Orbit gamefirst Anti-cheat

Mon, 06 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Mon, 06 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sun, 05 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 04 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 03 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 03 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 02 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via crafted requests that trigger a system crash.
Title CVE-2026-12166
References

Subscriptions

Little Orbit Gamefirst Anti-cheat
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-02T17:35:36.546Z

Reserved: 2026-06-12T19:40:24.620Z

Link: CVE-2026-12166

cve-icon Vulnrichment

Updated: 2026-07-02T17:35:32.221Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T10:45:05Z

Weaknesses