VU#639124: Multiple local privilege escalation vulnerabilities in Little Orbits GameFirst Anti-Cheat

2026-07-02T20:52:10Z42a607c6495b99ee01b065430383b8e9dba6a0cad313882d4299027e3556c0a0
BYOVDDBX revocationGFAC_Sys_x64.sys','SignalIo.sys','FastStone Image Viewer','shimHaskellIOCTLJP2MITMNULL-dereferenceNameConstraintsPSDSecure Boot bypassTLSUEFIWinREbuffer-overflowcrypton-x509-validationdenial-of-servicedevice-permissionsinteger-overflowkernel-driverlocal-privilege-escalationminifilterphysical-accessremote-code-executionthumbnailing

What happened

The document aggregates multiple high-impact vulnerabilities across Windows kernel drivers, desktop software, UEFI/ Secure Boot components, and a Haskell TLS library. Notable issues include local kernel privilege escalations and arbitrary kernel memory writes in the Little Orbit GFAC driver (including a NULL-deref DoS), critical remote-code-execution and memory-corruption bugs in FastStone Image Viewer (JP2 heap overflow and PSD integer overflow, triggered even via thumbnail generation), overly permissive device access and NULL-deref IOCTL handlers in SignalRGB’s SignalIo.sys, Secure Boot/Boot

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
42a607c6495b99ee01b065430383b8e9dba6a0cad313882d4299027e3556c0a0
Enrichment time
2026-07-02T20:52:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.