CVE-2026-90890
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local
CVSS
5.5
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 14, 2026 · Last modified: Sep 14, 2026 · CWE-822
Not enough EPSS history yet.
ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating system crash.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-339646.4 MED0.8%
——0An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.1dCVE-2026-839398.2 HIG22.2%
——7Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.5dCVE-2026-834987.8 HIG23.0%
——7Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.5dCVE-2026-800838.8 HIG13.5%
——4Untrusted pointer dereference in Windows Hyper-V allows an authorized attacker to execute code locally.5dCVE-2026-784516.8 MED37.1%
——11Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.4dCVE-2026-784448.1 HIG41.7%
——13Untrusted pointer dereference in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.4d