Untrusted Pointer Dereference Vulnerability in ASRock Polychrome SYNC/RGB Software
CVE-2026-90890

6.8MEDIUM

What is CVE-2026-90890?

The ASRock Polychrome SYNC/RGB software utility is vulnerable to untrusted pointer dereference, allowing authenticated local attackers to exploit the flaw. By sending specially crafted IOCTL requests, an attacker can trigger the driver to dereference an unvalidated pointer, potentially leading to an operating system crash and affecting system stability.

Affected Version(s)

ASRock Polychrome SYNC/RGB for MB 0 <= 1.0.118

ASRock Polychrome SYNC/RGB for VGA 0 <= 2.0.219

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.