Asrock's vulnerability profile centers on a narrow set of system-management and firmware utilities, including A-Tuning, F-Stream, and Restart to UEFI, that operate at a privileged level within consumer and workstation environments. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, driven by recurring weaknesses in permission assignment and privilege management that expose sensitive firmware and system controls. Defenders should prioritize firmware and BIOS-update channels for this vendor and restrict access to administrative utilities; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asrock over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10711HIGH The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expos | Oct 30, 2018 | 7.8 | 36 | NO | YES |
CVE-2018-10712HIGH The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expos | Oct 30, 2018 | 7.8 | 35 | NO | YES |
CVE-2018-10709HIGH The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expos | Oct 30, 2018 | 7.8 | 35 | NO | YES |
CVE-2018-10710HIGH The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expos | Oct 30, 2018 | 7.1 | 33 | NO | YES |
CVE-2020-14032CRITICAL ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM. | Jul 23, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-15368MEDIUM AsrDrv103.sys in the ASRock RGB Driver does not properly restrict access from user space, as demonstrated by triggering a triple fault via a request to zero CR3. | Jun 29, 2020 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asrock.
Media articles that mention a CVE ID that affects a product developed by Asrock — matched by CVE ID, not by vendor name.