Executive brief
OhSoft CoffeeZip is a file compression and extraction utility. A security flaw in this software allows malicious files to bypass Windows security warnings (Mark-of-the-Web) when they are extracted from a downloaded archive. If a user extracts and runs a file from a specially crafted archive, an attacker could gain full control over the user's computer.
Technical details
A Protection Mechanism Failure (CWE-693) exists in OhSoft CoffeeZip v4.8.0.0 and earlier. When the application extracts files from an archive that has been tagged with the 'Mark-of-the-Web' (indicating it was downloaded from the internet), it fails to apply that same security zone identifier to the resulting extracted files. This bypasses Windows SmartScreen and other security prompts that normally warn users before executing untrusted files. An attacker can exploit this by tricking a user into downloading a malicious archive and running an executable contained within it, leading to arbitrary code execution in the context of the current user.
Affected products
- OhSoft CoffeeZip 4.8.0.0 and earlier
Timeline
- 2026-07-22: advisory: CVE-2025-44090 published by NVD