Motherboards button
Motherboards
Graphics Card button
Graphics Card
Monitors button
Gaming Monitor
Power Supply button
Power Supply
Mini PC button
Mini PC
AIO Liquid Coolers button
AIO Liquid Coolers
Industrial PC button
Industrial PC
Server/WS button
Server/WS
Loading

We use cookies to offer you a more personalized and smoother experience.
By visiting this website, you agree to our use of cookies. If you prefer not to accept cookies or require more information, please visit our Privacy Policy.

Home > Security Center

Security Center

CVECVE-2026-90890, CVE-2026-90891
TitleVulnerabilities in ASRock
Polychrome Driver (MsIo64.sys)
Release date9/14/2026
Affected ProductsASRock Polychrome SYNC/RGB for MB version 1.0.118 and earlier
ASRock Polychrome SYNC/RGB for VGA version 2.0.219 and earlier
Advisory CategorySW
Severity rating【CVE-2026-90890】
6.8 (Medium) CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
5.5 (Medium) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

【CVE-2026-90891】
6.8 (Medium) CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
5.5 (Medium) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Report【CVE-2026-90890(Untrusted Pointer Dereference)】
Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
 
【CVE-2026-90891(Improper Access Control)】
Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.
Acknowledgements
Full Name: Taeyeong Kim
Organization: N/A (Independent Researcher)
Researcher Handle: Libera

Disclaimer

ASRock security advisory processes and policies may vary based on circumstances and are subject to change without prior notice. We do not guarantee a response to any particular issue or category of issues. The use of the information in this document or any related links is at your own risk.