ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update ASRock Polychrome SYNC/RGB for MB to a version later than 1.0.118 Update ASRock Polychrome SYNC/RGB for VGA to a version later than 2.0.219


Workaround

No workaround given by the vendor.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
Title ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference
Weaknesses CWE-822
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-14T11:19:45.694Z

Reserved: 2026-09-14T08:55:01.175Z

Link: CVE-2026-90890

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:41.354Z

cve-icon NVD

Status : Received

Published: 2026-09-14T11:17:07.493

Modified: 2026-09-14T12:17:51.413

Link: CVE-2026-90890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses