What is CVE-2025-44090?
A vulnerability in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code by downloading and executing a crafted archive file. Users should update the software immediately to mitigate the risk.
Azərbaycanca: OhSoft CoffeeZip v4.8.0.0 proqramında zəiflik aşkarlanıb. Bu, təcavüzkara xüsusi hazırlanmış arxiv faylını endirib icra etməklə sistemdə ixtiyari kod icra etməyə imkan verir. Təhlükəsizlik üçün dərhal proqramı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which version of OhSoft CoffeeZip is affected by CVE-2025-44090?
The CVE-2025-44090 vulnerability was discovered in OhSoft CoffeeZip v4.8.0.0.
What can an attacker achieve by exploiting CVE-2025-44090?
This vulnerability allows an attacker to execute arbitrary code on the system via a specially crafted archive file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.