Howyar Reloader UEFI bootloader vulnerable to unsigned software execution

Post Reply
Shane1145
Posts: 1624
Joined: Wed Sep 25, 2024 2:31 pm

Howyar Reloader UEFI bootloader vulnerable to unsigned software execution

Post by Shane1145 »

The Howyar UEFI Application "Reloader" (32-bit and 64-bit), distributed as part of SysReturn prior to version 10.2.02320240919, is vulnerable to the execution of arbitrary software from a hard-coded path. An attacker who successfully exploits this vulnerability can bypass the UEFI Secure Boot feature and execute unsigned code during the boot process in the UEFI context.


https://www.kb.cert.org/vuls/id/529659
Post Reply