CVE-2026-79298
PoC —3· 2 readsLocal Arbitrary Code Execution via UEFI Boot Loader in Howyar SysReturn
CVE-2026-79298 is a local arbitrary code execution vulnerability in Howyar Technologies' SysReturn system recovery software, affecting versions prior to 11.3.0.34. The flaw lies in the UEFI boot component BOOTia32.efi, which a local attacker can abuse by placing a crafted cloak32.dat file on the EFI System Partition (ESP); on the next boot, the loader processes this file and executes attacker-controlled code. Because execution occurs through the EFI boot component, an attacker who already has local access (physical or via malware with sufficient disk access) can gain code execution in the pre-boot environment, a strong position for privilege escalation and stealthy, persistent compromise. Any machine running an affected SysReturn version, typically PCs and recovery/kiosk deployments bundled with Howyar's restore solution, is affected. There is no evidence of in-the-wild exploitation and the flaw is not in CISA's KEV, but a public proof-of-concept is available on GitHub.
What to do: Upgrade SysReturn to version 11.3.0.34 or later on all managed machines. Restrict write access to the EFI System Partition where possible and audit endpoints for unexpected or modified BOOTia32.efi and cloak32.dat files, since a planted cloak32.dat is the exploit vector. Because exploitation requires local access, maintain endpoint hardening, malware defense, and physical access controls on affected systems.
| Howyar Technologies Inc. SysReturn | prior to 11.3.0.34 (fixed in v11.3.0.34) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.
In the news0 stories
No ingested article mentions this CVE yet.