CVE-2026-79298
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.4epss 0.2%
from disclosure to weapon0 days
Published on NVDSep 16
1st PoCJun 15
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 2
githubgithub.com/TheMalwareGuardian/UEFI-Security-Research-Howyar-SysReturn-NetCopy★ 2githubgithub.com/TheMalwareGuardian/CVE-2026-79298★ 2⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.