Impact
The vulnerability is an Untrusted Pointer Dereference in ASRock's Polychrome SYNC/RGB driver. Authenticated local users can craft a specific IOCTL request that forces the driver to dereference an unvalidated pointer, causing an operating system crash. This results in a denial‑of‑service condition that may bring down the system or graphics subsystem, but it does not directly grant code execution or privilege escalation, according to the description.
Affected Systems
ASRock Polychrome SYNC/RGB for Motherboard version 1.0.118 and earlier, and ASRock Polychrome SYNC/RGB for VGA version 2.0.219 and earlier. The issue affects both the motherboard and VGA implementations of the utility, causing the associated kernel driver to crash when a malicious IOCTL is processed.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. The exploit requires local authenticated access and an ability to issue IOCTL calls against the driver. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation today. If an attacker can obtain local privileges—for example, through credential compromise or local physical access—they could trigger the crash and disrupt system availability.
OpenCVE Enrichment