Impact
The vulnerability is an Improper Access Control flaw in ASRock Polychrome SYNC/RGB software. Authenticated local attackers can send a crafted IOCTL request that causes the driver to write to restricted I/O ports, resulting in a forced operating system reboot. This leads to denial of service for affected machines.
Affected Systems
ASRock Polychrome SYNC/RGB for Motherboards (updates later than 1.0.118) and ASRock Polychrome SYNC/RGB for VGA (updates later than 2.0.219).
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. The EPSS score of <1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. The attack requires an attacker to have local authenticated access and to send a specially crafted IOCTL request. No remote exploitation path is known. When the driver writes to an improperly protected I/O port, the system immediately reboots, causing a denial of service until the machine comes back online.
OpenCVE Enrichment