Improper Access Control in ASRock Polychrome SYNC/RGB Software
CVE-2026-90891

6.8MEDIUM

What is CVE-2026-90891?

The ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. exhibits an Improper Access Control issue. This vulnerability allows authenticated local attackers to exploit the software by sending specially crafted IOCTL requests. This can lead to unauthorized access to I/O ports, ultimately causing the affected driver to write to restricted areas, which may result in a forced reboot of the operating system. Adopting security measures to address this issue is crucial for system integrity and user protection.

Affected Version(s)

ASRock Polychrome SYNC/RGB for MB 0 <= 1.0.118

ASRock Polychrome SYNC/RGB for VGA 0 <= 2.0.219

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.