CVE-2026-12168: Little Orbit Gamefirst Anti-Cheat

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.

Affected products

  • Little Orbit Gamefirst Anti-Cheat: up to and including 2025-07-07

Published 2026-07-02. Last modified 2026-07-02.