CVE-2026-90891
Received Received - Intake

Improper Access Control in ASRock Polychrome SYNC/RGB

Vulnerability report for CVE-2026-90891, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: TWCERT/CC

Description

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
asrock polychrome_sync *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1256 The product provides software-controllable device functionality for capabilities such as power and clock management, but it does not properly limit functionality that can lead to modification of hardware memory or register bits, or the ability to observe physical side channels.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

ASRock Polychrome SYNC/RGB software has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to force the driver to write to restricted I/O ports, causing an unintended operating system reboot.

Detection Guidance

Detection of this vulnerability requires checking for the presence of ASRock Polychrome SYNC/RGB software and monitoring for unauthorized IOCTL requests. Inspect installed software on Windows systems via Control Panel or PowerShell commands like 'Get-WmiObject -Class Win32_Product'. Check running processes for 'PolychromeSYNC.exe' or similar. Monitor system logs for unexpected reboots or driver-related errors.

Impact Analysis

This vulnerability allows attackers with local access to cause system instability by forcing unexpected reboots. It does not directly expose data but disrupts system availability and could lead to data loss or corruption during forced shutdowns.

Compliance Impact

This vulnerability primarily impacts system availability and integrity. While it does not directly violate GDPR or HIPAA data protection requirements, repeated forced reboots could disrupt critical operations, potentially leading to compliance issues if they affect data processing or availability.

Mitigation Strategies

Immediately uninstall ASRock Polychrome SYNC/RGB software from affected systems. Disable the driver if removal is not possible. Apply patches or updates from ASRock if available. Restrict local user permissions to prevent unauthorized access. Monitor systems for signs of exploitation or forced reboots.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90891. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart