Impact
An exploitation flaw exists in OhSoft CoffeeZip version 4.8.0.0 that permits an attacker to run arbitrary code by delivering a specially crafted archive file. Once the user downloads and extracts or executes the malicious archive, the application processes it in a way that allows the embedded code to be executed on the victim’s system, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
The vulnerability is limited to OhSoft CoffeeZip ver. 4.8.0.0. No other product versions are listed as affected, and no vendor information is provided beyond the product name. Users operating this specific software version should be aware that the issue applies directly to them.
Risk and Exploitability
The flaw carries a high potential impact, as arbitrary code execution is a severe capability. The CVSS score is 8.8, indicating a high severity level, but the EPSS score of <1% suggests a low probability of exploitation at present. The attack vector is most likely local or requires user interaction, where an attacker supplies a malicious archive for the user to open or extract. Because the software automatically processes the archive contents, if an end user runs the file, the malicious code will execute, allowing the adversary to take complete control of the system. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment