CVE-2025-14304: ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure
Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14304?
CVE-2025-14304 is considered a high-severity vulnerability due to the potential for unauthenticated physical attacks.
How do I fix CVE-2025-14304?
To remediate CVE-2025-14304, ensure that IOMMU is properly enabled in the motherboard's BIOS settings.
Which devices are affected by CVE-2025-14304?
CVE-2025-14304 affects certain ASRock and its subsidiaries' motherboard models.
What type of attack is possible with CVE-2025-14304?
CVE-2025-14304 allows attackers with physical access to read and write arbitrary physical memory using a DMA-capable PCIe device.
Is there a workaround for CVE-2025-14304?
The primary workaround for CVE-2025-14304 is to enable IOMMU in the BIOS settings to mitigate the vulnerability.