CVE-2025-14304: Asrock Intel 500 Chipset Motherboard

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.

Affected products

  • Asrock Intel 500 Chipset Motherboard: version 0 only
  • Asrock Intel 600 Chipset Motherboard: version 0 only
  • Asrock Intel 700 Chipset Motherboard: version 0 only
  • Asrock Intel 800 Chipset Motherboard: version 0 only
  • Asrockind Intel 500 Chipset Motherboard: version 0 only
  • Asrockind Intel 600 Chipset Motherboard: version 0 only
  • Asrockind Intel 700 Chipset Motherboard: version 0 only
  • Asrockind Intel 800 Chipset Motherboard: version 0 only
  • Asrockrack Intel 500 Chipset Motherboard: version 0 only
  • Asrockrack Intel 600 Chipset Motherboard: version 0 only
  • Asrockrack Intel 700 Chipset Motherboard: version 0 only
  • Asrockrack Intel 800 Chipset Motherboard: version 0 only

Published 2025-12-17. Last modified 2026-10-07.