Junglewise Threat Intelligence

CVE-2026-79298: Howyar SysReturn UEFI Secure Boot bypass in BOOTia32.efi

CVE-2026-79298 · Severity: high · CVSS 8.4 · Published 2026-09-16

Executive brief

SysReturn is a boot utility used to manage system recovery and deployment on enterprise systems. A flaw in the IA-32 boot loader allows a local attacker with access to the ESP (EFI System Partition) to bypass Secure Boot protections and execute arbitrary code with firmware-level privileges, potentially compromising the entire system before the operating system loads.

Technical details

CVE-2026-79298 is a UEFI Secure Boot bypass vulnerability in the BOOTia32.efi boot loader component of SysReturn. The issue stems from an incomplete remediation of a prior vulnerability (CVE-2024-7344) affecting the RxPE custom PE loader; the IA-32 boot path was never patched and continues to ship the same revoked PE loader. An attacker with local access to the ESP can craft a malicious cloak32.dat file to trigger arbitrary code execution during the boot process. The vulnerability requires physical or local access to modify the ESP but bypasses Secure Boot protections entirely, enabling pre-OS execution with firmware privileges.

Affected products

  • Howyar Technologies Inc SysReturn prior to 11.3.0.34

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Fixed in version 11.3.0.34

References