CVE-2026-90891: ASRock|ASRock Polychrome SYNC/RGB software utility - Improper Access Control
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ASRock Polychrome SYNC/RGB for MBto a version that resolves this vulnerability.Fixed in later than 1.0.118 - Upgrade
Upgrade
ASRock Polychrome SYNC/RGB for VGAto a version that resolves this vulnerability.Fixed in later than 2.0.219
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems with the ASRock Polychrome SYNC/RGB software utility installed are exposed. Exploitation requires an authenticated local attacker with low privileges.
What does an attacker need to do to trigger the impact?
The attacker must be able to run locally as an authenticated user and send a specially crafted IOCTL request to the affected driver. Successful exploitation can force the operating system to reboot.
Does this issue allow data theft or modification?
The provided impact information identifies availability impact only: a forced operating system reboot. It does not identify confidentiality or integrity impact.