CVE-2020-15368 describes a local privilege escalation vulnerability in the ASRock RGB Driver (AsrDrv103.sys) that allows user-mode applications to trigger a triple fault by attempting to zero CR3. This medium-severity flaw (CVSS 5.5) has a low attack complexity and requires local user access, but could lead to a denial of service. While there is no known public exploit code or active exploitation, the vulnerability has garnered significant community discussion and media coverage, though the media articles appear to be broadly related to ICS/SCADA threats rather than this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:asrock:rgb_driver_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.