CVE-2026-79298: Howyar Technologies Inc SysReturn vulnerability
An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Howyar Technologies Inc SysReturnto a version that resolves this vulnerability.Fixed in 11.3.0.34
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue requires local access. The attacker must be able to place or modify a crafted cloak32.dat file on the EFI System Partition (ESP) for use with BOOTia32.efi.
Which SysReturn versions are affected?
SysReturn versions prior to 11.3.034 are affected. The issue is fixed in version 11.3.0.34.
How can I check whether a system may be exposed?
Check the installed SysReturn version and inspect the ESP for BOOTia32.efi and cloak32.dat. Systems running a version prior to 11.3.034 with attacker-writable access to the ESP may be exposed.