Vulnerability Description
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asrock | Rgb Driver Firmware | - |
| Asrock | Rgb Driver | - |
References
- https://codetector.org/post/asrock_rgb_driver/Third Party Advisory
- https://github.com/stong/CVE-2020-15368?tab=readme-ov-file
- https://codetector.org/post/asrock_rgb_driver/Third Party Advisory
- https://github.com/stong/CVE-2020-15368?tab=readme-ov-file
FAQ
What is CVE-2020-15368?
CVE-2020-15368 is a vulnerability with a CVSS score of 5.5 (MEDIUM). AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3.
How severe is CVE-2020-15368?
CVE-2020-15368 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15368?
Check the references section above for vendor advisories and patch information. Affected products include: Asrock Rgb Driver Firmware, Asrock Rgb Driver.