Impact
The vulnerability resides in NCH Software ExpressZip version 11.29, where an attacker can supply a maliciously crafted archive file that, when the application downloads and extracts it, results in execution of arbitrary code on the host system. The flaw enables a remote attacker to gain full control without required credentials, impacting confidentiality, integrity, and availability.
Affected Systems
NCH Software ExpressZip 11.29 is affected. No other vendor or product versions are listed. Users running this specific version are at risk.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity, while the EPSS score of less than 1% shows a low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker delivering a crafted archive that the application processes. Because the flaw permits arbitrary code execution, the attacker can achieve a full system compromise. Until a vendor update is issued, the risk remains elevated.
OpenCVE Enrichment