ASRock records
6 published records for vendor asrock.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-732 Incorrect Permission Assignment for Critical Resource3
- CWE-269 Improper Privilege Management2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-14032No exploit | ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.asrock · box-r1000 firmware · CWE-269 | Critical9.8 | — | 2.1% | Jul 23, 2021 |
31Monitor | CVE-2018-10711Proof of concept | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210,asrock · a-tuning · CWE-20 | High7.8 | — | 1.5% | Oct 30, 2018 |
31Monitor | CVE-2018-10712Proof of concept | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210,asrock · a-tuning · CWE-732 | High7.8 | — | 1.3% | Oct 30, 2018 |
31Monitor | CVE-2018-10709Proof of concept | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210,asrock · a-tuning · CWE-732 | High7.8 | — | 1.2% | Oct 30, 2018 |
28Monitor | CVE-2018-10710Proof of concept | The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210,asrock · a-tuning · CWE-732 | High7.1 | — | 1.0% | Oct 30, 2018 |
22Monitor | CVE-2020-15368Proof of concept | AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via aasrock · rgb driver firmware · CWE-269 | Medium5.5 | — | 1.4% | Jun 29, 2020 |
- CVE-2020-1403240Plan
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.
CriticalCVSS 9.8No exploitEPSS 2%asrock · box-r1000 firmwareJul 23, 2021
- CVE-2018-1071131Monitor
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210,
HighCVSS 7.8Proof of conceptEPSS 2%asrock · a-tuningOct 30, 2018
- CVE-2018-1071231Monitor
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210,
HighCVSS 7.8Proof of conceptEPSS 1%asrock · a-tuningOct 30, 2018
- CVE-2018-1070931Monitor
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210,
HighCVSS 7.8Proof of conceptEPSS 1%asrock · a-tuningOct 30, 2018
- CVE-2018-1071028Monitor
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210,
HighCVSS 7.1Proof of conceptEPSS 1%asrock · a-tuningOct 30, 2018
- CVE-2020-1536822Monitor
AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a
MediumCVSS 5.5Proof of conceptEPSS 1%asrock · rgb driver firmwareJun 29, 2020