Security Advisory

CVE-2026-90891

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-14 10:37:57
Last updated 2026-09-14 11:19:45
Assigner twcert
CVSS score 6.8
State PUBLISHED

Description

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced operating system reboot.