CVE-2026-12168 Details
Description
An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.
A vulnerability in the Little Orbit GamersFirst Anti-Cheat (GFAC) driver, specifically in 'GFAC_Sys_x64.sys', allows local attackers to escalate privileges to SYSTEM and execute arbitrary code in kernel mode. This vulnerability arises from improper validation of user-supplied memory addresses in messages sent through a minifilter communication port, enabling attackers to overwrite critical kernel structures, such as process security tokens.
Users should treat 'GFAC_Sys_x64.sys' as vulnerable and remove or disable it if GFAC functionality is not required. For systems where GFAC-dependent games are installed, restrict access to trusted users and monitor for unauthorized connections to the GFAC minifilter communication port.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 2, 2026CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FzRsLLaSheR/CVE-2026-12166_CVE-2026-12167_CVE-2026-12168 | [email protected] | BundleTechnical Description |
| https://kb.cert.org/vuls/id/639124 | [email protected] | AdvisoryBundleRemedy |
| https://www.littleorbit.com/ | [email protected] | Vendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Little Orbit GamersFirst Anti-Cheat | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | CVE Modified | CISA-ADP |
| Jul 2, 2026 | New CVE Received | [email protected] |
Volerion