CVE-2026-79298

Howyar Technologies Inc · SysReturn

Howyar Technologies Inc SysReturn versions prior to 11.3.034 contain a vulnerability allowing local attackers to execute arbitrary code via a crafted cloak32.dat file on the EFI System Partition.

Executive summary

A high-severity local code execution vulnerability in Howyar Technologies Inc SysReturn allows attackers to compromise system integrity via the EFI partition.

Vulnerability

This vulnerability involves improper handling of EFI files, specifically allowing an attacker with local access to execute arbitrary code by manipulating the BOOTia32.efi loader using a crafted cloak32.dat file located on the EFI System Partition. The vulnerability is accessible to unauthenticated local attackers as indicated by the CVSS vector.

Business impact

The ability to execute arbitrary code at the EFI level allows an attacker to gain persistent control over the affected system, effectively bypassing operating system security controls. Given the CVSS score of 8.4, this vulnerability represents a significant risk of total system compromise, potentially leading to unauthorized data access, system disruption, and the establishment of deep-level persistence that survives standard OS reinstallation.

Remediation

Immediate Action: Update Howyar Technologies Inc SysReturn to version 11.3.034 or later to apply the necessary security fixes.

Proactive Monitoring: Monitor EFI System Partition integrity and audit logs for unauthorized file modifications or suspicious boot-time activity.

Compensating Controls: Restrict local physical and logical access to the server environment and ensure that UEFI Secure Boot is enabled and properly configured to prevent the execution of unsigned or malicious bootloaders.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, attributed to the security research documented in the referenced GitHub repositories.

Analyst recommendation

This vulnerability presents a severe risk due to its potential for persistent, low-level system compromise. Organizations utilizing SysReturn must prioritize patching to version 11.3.034 immediately to eliminate the attack vector. Given the availability of a public proof-of-concept, the window for remediation is limited, and administrators should verify the success of the update across all affected deployments as soon as possible.

More Howyar Technologies Inc CVEs

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.4 (3.1)
  4. Analyst report written

Sources