CVE-2025-14304 HIGH

CVE-2025-14304: ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure

Vendor Asrock
Product Intel 500 chipset motherboard
Weakness CWE-693
Published December 17, 2025
Last update December 17, 2025

CVSS base score

7.0/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded.

Key dates

02Disclosure timeline

December 17, 2025 CVE published
December 17, 2025 Record updated