CVE-2026-90891

Summary

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.

Affected Software

VendorProductVersion RangeStatus
ASRockASRock Polychrome SYNC/RGB for MB0 <= 1.0.118affected
ASRockASRock Polychrome SYNC/RGB for VGA0 <= 2.0.219affected

Weaknesses

  • CWE-1256: CWE-1256 Improper Restriction of Software Interfaces to Hardware

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References