CVE-2026-90890
Received
Received - Intake
ASRock Polychrome SYNC Untrusted Pointer Dereference
Vulnerability report for CVE-2026-90890, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-14
Last updated on: 2026-09-14
Assigner: TWCERT/CC
Description
Description
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| asrock | polychrome_sync | * |
| asrock | polychrome_sync_rgb | to 1.0.118 (exc) |
| asrock | polychrome_sync_rgb | to 2.0.219 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-822 | The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer. |