CVE-2026-90890: ASRock|ASRock Polychrome SYNC/RGB software utility - Untrusted Pointer Dereference
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ASRock Polychrome SYNC/RGB for MBto a version that resolves this vulnerability.Fixed in later than 1.0.118 - Upgrade
Upgrade
ASRock Polychrome SYNC/RGB for VGAto a version that resolves this vulnerability.Fixed in later than 2.0.219
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems with the ASRock Polychrome SYNC/RGB software utility installed are exposed. Exploitation requires an attacker to already have authenticated local access.
What does an attacker need to do to trigger the vulnerability?
The attacker must send a specially crafted IOCTL request to the affected driver. The vulnerability involves dereferencing an unvalidated pointer.
What is the likely impact of successful exploitation?
Successful exploitation can crash the operating system, causing a denial of service. The provided information does not indicate confidentiality or integrity impact.