Executive brief
ExpressZip is a file compression and extraction utility. A security flaw in the software allows attackers to bypass Windows security warnings (Mark-of-the-Web) when a user extracts and runs files from a malicious archive. If a user is tricked into opening a specially crafted ZIP file, an attacker could gain full control over the user's computer and execute malicious code.
Technical details
A protection mechanism failure (CWE-693) exists in NCH Software ExpressZip version 11.29 and earlier. The application fails to propagate the Mark-of-the-Web (MotW) attribute from a downloaded archive to the files extracted from it. This bypasses Windows SmartScreen and other security zone-based warnings that typically prevent the execution of untrusted files from the internet. An attacker can exploit this by delivering a crafted archive via the network; if the victim extracts the contents and executes a malicious file within, the attacker can achieve arbitrary code execution in the context of the current user.
Affected products
- NCH Software ExpressZip 11.29 and earlier
Timeline
- 2026-07-22: advisory: CVE-2025-44089 published by NVD/MITRE