CVE-2026-12168Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-02: 1Technical Details · 2026-07-02: 107-02
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • OJOBIT@0J0BIT
    Disclosure

    Local Users Can Write Arbitrary Kernel Memory Through Little Orbit Anti-Cheat Driver CVE-2026-12166 is a NULL pointer dereference that crashes the system with a blue screen. CVE-2026-12167 exposes the driver's minifilter communication port to any local user - no proper access control means even low-privileged accounts can connect and invoke privileged functions. CVE-2026-12168 is the crown jewel for an attacker: a write-what-where condition where the driver writes attacker-supplied data to memory addresses without validation. https://news.ojobit.com/story/little-orbit-gfac-driver-local-privilege-escalation-unpatched-69a1e8

    Post summary

    The post discloses three new kernel‑level CVEs in the Little Orbit Anti‑Cheat driver, detailing their types and impact, but offers no PoC, exploit code, or patch information.

    0000065
    2 followersView on X

Explore more