CVE-2025-44089

8.8

NCH Software · ExpressZip

NCH Software ExpressZip v11.29 is vulnerable to arbitrary code execution through the processing of a crafted archive file.

Executive summary

A high severity remote code execution vulnerability in NCH Software ExpressZip v11.29 exposes systems to complete compromise through user interaction.

Vulnerability

This vulnerability involves improper handling of archive files, allowing an unauthenticated attacker who leverages user interaction to achieve arbitrary code execution.

Business impact

A successful exploit of this vulnerability can lead to total system compromise, resulting in unauthorized data access, system modification, or denial of service. The CVSS score of 8.8 reflects the high potential for confidentiality, integrity, and availability impact if an end user downloads and executes a malicious archive file.

Remediation

Immediate Action: Check the vendor advisory for official patches or updates, and avoid opening untrusted archive files with ExpressZip.

Proactive Monitoring: Monitor endpoint activity for anomalous process creation spawned by the ExpressZip application.

Compensating Controls: Deploy endpoint detection and response solutions to block unauthorized execution chains originating from archive utilities.

Exploitation status

Public Exploit Available: Yes, a public reference writeup exists via GitHub.

Analyst recommendation

Given the high severity and potential for total system compromise, administrators must monitor the vendor advisory closely for an official patch. Users should exercise extreme caution and refrain from downloading or extracting untrusted archive files until a permanent fix is applied.

Sources