Description
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (System crash)
Action: Patch
AI Analysis

Impact

The vulnerability is an Untrusted Pointer Dereference in ASRock's Polychrome SYNC/RGB driver. Authenticated local users can craft a specific IOCTL request that forces the driver to dereference an unvalidated pointer, causing an operating system crash. This results in a denial‑of‑service condition that may bring down the system or graphics subsystem, but it does not directly grant code execution or privilege escalation, according to the description.

Affected Systems

ASRock Polychrome SYNC/RGB for Motherboard version 1.0.118 and earlier, and ASRock Polychrome SYNC/RGB for VGA version 2.0.219 and earlier. The issue affects both the motherboard and VGA implementations of the utility, causing the associated kernel driver to crash when a malicious IOCTL is processed.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. The exploit requires local authenticated access and an ability to issue IOCTL calls against the driver. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation today. If an attacker can obtain local privileges—for example, through credential compromise or local physical access—they could trigger the crash and disrupt system availability.

Generated by OpenCVE AI on September 15, 2026 at 14:31 UTC.

Remediation

Vendor Solution

Update ASRock Polychrome SYNC/RGB for MB to a version later than 1.0.118 Update ASRock Polychrome SYNC/RGB for VGA to a version later than 2.0.219


OpenCVE Recommended Actions

  • Update ASRock Polychrome SYNC/RGB for MB to a version later than 1.0.118.
  • Update ASRock Polychrome SYNC/RGB for VGA to a version later than 2.0.219.
  • Disable or uninstall the Polychrome SYNC/RGB software utility to prevent the vulnerable driver from loading until a patched version is available.
  • Limit local user privileges to reduce the likelihood that an authenticated local attacker can send malicious IOCTL requests.

Generated by OpenCVE AI on September 15, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Asrock
Asrock asrock Polychrome Sync/rgb For Mb
Asrock asrock Polychrome Sync/rgb For Vga
Vendors & Products Asrock
Asrock asrock Polychrome Sync/rgb For Mb
Asrock asrock Polychrome Sync/rgb For Vga

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
Title ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference
Weaknesses CWE-822
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asrock Asrock Polychrome Sync/rgb For Mb Asrock Polychrome Sync/rgb For Vga
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-14T11:19:45.694Z

Reserved: 2026-09-14T08:55:01.175Z

Link: CVE-2026-90890

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:41.354Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:07.493

Modified: 2026-09-18T19:15:11.780

Link: CVE-2026-90890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:28Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference