We use cookies to offer you a more personalized and smoother experience.
By visiting this website, you agree to our use of cookies. If you prefer not to accept cookies or require more information, please visit our Privacy Policy.
| CVE | CVE-2026-90890, CVE-2026-90891 |
|---|---|
| Title | Vulnerabilities in ASRock Polychrome Driver (MsIo64.sys) |
| Release date | 9/14/2026 |
| Affected Products | ASRock Polychrome SYNC/RGB for MB version 1.0.118 and earlier ASRock Polychrome SYNC/RGB for VGA version 2.0.219 and earlier |
| Advisory Category | SW |
| Severity rating | 【CVE-2026-90890】 6.8 (Medium) CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N 5.5 (Medium) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H 【CVE-2026-90891】 6.8 (Medium) CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N 5.5 (Medium) CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| Report | 【CVE-2026-90890(Untrusted Pointer Dereference)】 Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash. 【CVE-2026-90891(Improper Access Control)】 Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot. Acknowledgements Full Name: Taeyeong Kim Organization: N/A (Independent Researcher) Researcher Handle: Libera |
ASRock security advisory processes and policies may vary based on circumstances and are subject to change without prior notice. We do not guarantee a response to any particular issue or category of issues. The use of the information in this document or any related links is at your own risk.