Untrusted Pointer Dereference Vulnerability in ASRock Polychrome SYNC/RGB Software
CVE-2026-90890
6.8MEDIUM
What is CVE-2026-90890?
The ASRock Polychrome SYNC/RGB software utility is vulnerable to untrusted pointer dereference, allowing authenticated local attackers to exploit the flaw. By sending specially crafted IOCTL requests, an attacker can trigger the driver to dereference an unvalidated pointer, potentially leading to an operating system crash and affecting system stability.
Affected Version(s)
ASRock Polychrome SYNC/RGB for MB 0 <= 1.0.118
ASRock Polychrome SYNC/RGB for VGA 0 <= 2.0.219
