Description
The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionality via a communication interface that lacks appropriate access restrictions.
Published: 2026-07-02
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The GFAC_Sys_x64.sys driver in Little Orbit’s GameFirst anti‑cheat contains a Minifilter communication port that does not enforce proper access restrictions. This allows a local attacker who can run code on the machine to connect to the port and invoke privileged driver operations, effectively executing kernel‑mode code and escalating privileges. The flaw represents an access‑control violation identified as CWE‑284.

Affected Systems

All installations of Little Orbit GameFirst anti‑cheat that include the GFAC_Sys_x64.sys driver are affected. No specific version range is provided, so any version currently deployed is potentially vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 7.8 and an EPSS score of less than 1%, indicating a high severity but a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack vector is local; a malicious user who can run code on the target machine can contact the Minifilter port and trigger privileged driver functionality, leading to kernel‑mode privilege escalation.

Generated by OpenCVE AI on July 22, 2026 at 13:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest driver update or patch from Little Orbit that removes the unchecked communication port.
  • If no patch is available, restrict access to the GFAC_Sys_x64.sys Minifilter port so that only privileged processes may communicate with it, using OS access controls or group policy.
  • Monitor driver load activity and the anti‑cheat driver for anomalous behavior, and enable auditing to detect attempts to exploit the port.

Generated by OpenCVE AI on July 22, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 17 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 12 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 10 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-640

Tue, 07 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-640

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Little Orbit
Little Orbit gamefirst Anti-cheat
Vendors & Products Little Orbit
Little Orbit gamefirst Anti-cheat

Mon, 06 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 06 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-272
CWE-284

Sun, 05 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-272
CWE-284

Sat, 04 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 02 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 02 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionality via a communication interface that lacks appropriate access restrictions.
Title CVE-2026-12167
References

Subscriptions

Little Orbit Gamefirst Anti-cheat
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-02T17:34:47.803Z

Reserved: 2026-06-12T19:40:33.666Z

Link: CVE-2026-12167

cve-icon Vulnrichment

Updated: 2026-07-02T17:34:37.820Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:45:02Z

Weaknesses

No weakness.