CVE-2025-14304: Asrock Intel 500 Chipset Motherboard
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.
Affected products
- Asrock Intel 500 Chipset Motherboard: version 0 only
- Asrock Intel 600 Chipset Motherboard: version 0 only
- Asrock Intel 700 Chipset Motherboard: version 0 only
- Asrock Intel 800 Chipset Motherboard: version 0 only
- Asrockind Intel 500 Chipset Motherboard: version 0 only
- Asrockind Intel 600 Chipset Motherboard: version 0 only
- Asrockind Intel 700 Chipset Motherboard: version 0 only
- Asrockind Intel 800 Chipset Motherboard: version 0 only
- Asrockrack Intel 500 Chipset Motherboard: version 0 only
- Asrockrack Intel 600 Chipset Motherboard: version 0 only
- Asrockrack Intel 700 Chipset Motherboard: version 0 only
- Asrockrack Intel 800 Chipset Motherboard: version 0 only
Published 2025-12-17. Last modified 2026-10-07.