Description
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service – system reboot
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an Improper Access Control flaw in ASRock Polychrome SYNC/RGB software. Authenticated local attackers can send a crafted IOCTL request that causes the driver to write to restricted I/O ports, resulting in a forced operating system reboot. This leads to denial of service for affected machines.

Affected Systems

ASRock Polychrome SYNC/RGB for Motherboards (updates later than 1.0.118) and ASRock Polychrome SYNC/RGB for VGA (updates later than 2.0.219).

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. The EPSS score of <1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. The attack requires an attacker to have local authenticated access and to send a specially crafted IOCTL request. No remote exploitation path is known. When the driver writes to an improperly protected I/O port, the system immediately reboots, causing a denial of service until the machine comes back online.

Generated by OpenCVE AI on September 15, 2026 at 14:59 UTC.

Remediation

Vendor Solution

Update ASRock Polychrome SYNC/RGB for MB to a version later than 1.0.118 Update ASRock Polychrome SYNC/RGB for VGA to a version later than 2.0.219


OpenCVE Recommended Actions

  • Update ASRock Polychrome SYNC/RGB for Motherboards to a version newer than 1.0.118.
  • Update ASRock Polychrome SYNC/RGB for VGA to a version newer than 2.0.219.
  • Restrict local users’ privileges or disable the Polychrome utility on critical systems to limit the ability of an attacker to issue the vulnerable IOCTL calls.

Generated by OpenCVE AI on September 15, 2026 at 14:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Asrock
Asrock asrock Polychrome Sync/rgb For Mb
Asrock asrock Polychrome Sync/rgb For Vga
Vendors & Products Asrock
Asrock asrock Polychrome Sync/rgb For Mb
Asrock asrock Polychrome Sync/rgb For Vga

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.
Title ASRock|ASRock Polychrome SYNC/RGB software utility - Improper Access Control
Weaknesses CWE-1256
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Asrock Asrock Polychrome Sync/rgb For Mb Asrock Polychrome Sync/rgb For Vga
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-14T11:19:45.358Z

Reserved: 2026-09-14T08:55:02.582Z

Link: CVE-2026-90891

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:37.321Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:07.643

Modified: 2026-09-18T19:15:11.780

Link: CVE-2026-90891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:25Z

Weaknesses
  • CWE-1256

    Improper Restriction of Software Interfaces to Hardware Features