Howyar SysReturn
cpe:2.3:a:howyar:sysreturn:*:*:*:*:*:*:*
- < 10.2.023_20240919
A vulnerability in the Howyar UEFI Application 'Reloader' allows for the execution of unsigned software from a hard-coded path, bypassing UEFI Secure Boot. This issue affects both 32-bit and 64-bit versions of the application, which is distributed as part of several real-time system recovery software suites. The vulnerability arises because the Reloader application does not use standard UEFI functions to load applications securely, enabling the execution of arbitrary code during the boot process with high privileges.
Exploitation of this vulnerability allows for the execution of unsigned code during the UEFI boot process, bypassing Secure Boot. This could lead to the installation of a UEFI bootkit, a type of malware that operates with high privileges and can evade detection by traditional security measures and even some endpoint detection and response (EDR) tools.
To reproduce this vulnerability, replace a default UEFI bootloader binary on the EFI system partition with the vulnerable 'reloader.efi' application. Then, copy a file named 'cloak.dat' containing an unsigned UEFI application into a path on the EFI system partition that the bootloader will access. After rebooting the system, the bootloader will load and execute the unsigned application, bypassing Secure Boot.
Users should update to the latest version of the Howyar Reloader application, as well as apply the January 2025 UEFI revocation updates from Microsoft, which are available through the Microsoft Update Catalog. Instructions for verifying and applying these updates can be found on the ESET website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.