Impact
The vulnerability resides in how the SysReturn firmware module processes a crafted cloak32.dat file when the BOOTia32.efi loader is present. An attacker who can write a malicious cloak32.dat to the ESP and has local access to the UEFI shell can cause the firmware to load arbitrary instructions from that file, resulting in execution of code with the privileges of the firmware environment. This flaw is identified as a CWE‑693 weakness in the control of system configuration or data.
Affected Systems
Affected products are SysReturn from Howyar Technologies Inc. Firmware versions older than 11.3.034 (prior to 11.3.0.34) are vulnerable; the issue is fixed in firmware version 11.3.0.34 and later.
Risk and Exploitability
The CVSS score is 8.4, indicating high severity. The EPSS score is less than 1%, showing a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. To exploit the flaw an attacker needs local physical or logical access that allows them to write to the EFI System Partition so they can place the malicious cloak32.dat and trigger BOOTia32.efi during boot. If successful, the firmware will execute attacker‑supplied code, potentially compromising the device and risking further attacks.
OpenCVE Enrichment