CVE-2026-90891 Details
Description
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.
A vulnerability has been identified in the ASRock Polychrome SYNC/RGB software utility, both for motherboards and graphics cards, prior to specific version limits. This vulnerability allows authenticated local attackers to send specially crafted IOCTL requests that manipulate the driver into writing to improperly restricted I/O ports. The consequence of this action is a forced reboot of the operating system.
Users are advised to update the ASRock Polychrome SYNC/RGB software for motherboards to a version later than 1.0.118 and for graphics cards to a version later than 2.0.219.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-11204-6b1c6-2.html | [email protected] | AdvisoryBundleRemedy |
| https://www.twcert.org.tw/tw/cp-132-11205-f6677-1.html | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1256 | Improper Restriction of Software Interfaces to Hardware Features | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ASRock Polychrome SYNC | <= 1.0.118 (semver) |
CPE
Remediation
| |
| ASRock Polychrome RGB | <= 2.0.219 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion