ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update ASRock Polychrome SYNC/RGB for MB to a version later than 1.0.118 Update ASRock Polychrome SYNC/RGB for VGA to a version later than 2.0.219


Workaround

No workaround given by the vendor.

History

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
Title ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference
Weaknesses CWE-822
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-14T11:19:45.694Z

Reserved: 2026-09-14T08:55:01.175Z

Link: CVE-2026-90890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T11:17:07.493

Modified: 2026-09-14T11:17:07.493

Link: CVE-2026-90890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses