Vulnerability Description
An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/TheMalwareGuardian/CVE-2026-79298
- https://github.com/TheMalwareGuardian/UEFI-Security-Research-Howyar-SysReturn-Ne
- https://github.com/TheMalwareGuardian/UEFI-Security-Research-Howyar-SysReturn-Ne
FAQ
What is CVE-2026-79298?
CVE-2026-79298 is a vulnerability with a CVSS score of 8.4 (HIGH). An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file o...
How severe is CVE-2026-79298?
CVE-2026-79298 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-79298?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.