ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update ASRock Polychrome SYNC/RGB for MB to a version later than 1.0.118 Update ASRock Polychrome SYNC/RGB for VGA to a version later than 2.0.219
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash. | |
| Title | ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference | |
| Weaknesses | CWE-822 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-09-14T10:35:49.622Z
Reserved: 2026-09-14T08:55:01.175Z
Link: CVE-2026-90890
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses