Executive brief
ASRock Polychrome SYNC/RGB is a software utility that controls RGB lighting and system settings on ASRock motherboards and graphics cards. An authenticated local attacker can exploit an access control flaw in the driver to write to restricted I/O ports, forcing an unexpected system reboot and causing operational disruption.
Technical details
The vulnerability is an improper access control issue (CWE-284) in the ASRock Polychrome SYNC/RGB driver. An authenticated local attacker can send a specially crafted IOCTL request that bypasses validation checks, allowing the driver to write to improperly restricted I/O ports. This results in a forced operating system reboot. Attack requires local access with user-level privileges and no user interaction. Affected versions: Polychrome SYNC/RGB for MB version 1.0.118 and earlier, and for VGA version 2.0.219 and earlier. Patches are available in versions later than 1.0.118 (MB) and 2.0.219 (VGA).
Affected products
- ASRock Polychrome SYNC/RGB for MB 1.0.118 and earlier
- ASRock Polychrome SYNC/RGB for VGA 2.0.219 and earlier
Timeline
- 2026-09-14: disclosed