Description
An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.
Published: 2026-07-02
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the GFAC_Sys_x64.sys driver of Little Orbit GameFirst Anti‑Cheat allows a local attacker to send crafted messages through the driver’s Minifilter communication port, culminating in kernel‑mode code execution with SYSTEM privileges. This improper validation of input gives the attacker the ability to run arbitrary code, install malware, or modify system settings. The weakness is captured by CWE‑284 (Improper Access Control) and CWE‑285 (Elevation of Privilege).

Affected Systems

All installations of Little Orbit GameFirst Anti‑Cheat that include the GFAC_Sys_x64.sys driver are exposed; the vendor has not defined specific affected versions, so any release containing this driver is considered vulnerable until a patch is released. The driver operates on Windows platforms where it is installed.

Risk and Exploitability

The CVSS score of 7.8 classifies the defect as high severity, but the EPSS score of less than 1% indicates a very low probability of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. It requires local user access to communicate with the driver’s Minifilter port, with no mentioned remote exploitation pathway. The risk is moderate but the impact of successful exploitation—SYSTEM‑level code execution—is severe.

Generated by OpenCVE AI on July 17, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a vendor‑issued patch or upgrade the GFAC driver to a non‑vulnerable release as soon as it becomes available
  • If a patch is not currently available, uninstall or disable the GFAC_Sys_x64.sys driver to eliminate the attack surface
  • Enforce least‑privilege policies for local users and implement strict device‑management controls to reduce the likelihood of unauthorized driver interaction

Generated by OpenCVE AI on July 17, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 17 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 15 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 13 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sun, 12 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 11 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 10 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 08 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 08 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Little Orbit
Little Orbit gamefirst Anti-cheat
Vendors & Products Little Orbit
Little Orbit gamefirst Anti-cheat

Sun, 05 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 04 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Sat, 04 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 03 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 03 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 02 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 02 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.
Title CVE-2026-12168
References

Subscriptions

Little Orbit Gamefirst Anti-cheat
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-02T17:36:23.423Z

Reserved: 2026-06-12T19:40:44.862Z

Link: CVE-2026-12168

cve-icon Vulnrichment

Updated: 2026-07-02T17:36:19.971Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T10:45:05Z

Weaknesses