What is the EXE file format?
A file with the .exe extension contains a compiled program and its resources for Microsoft Windows, DOS, or (historically) OS/2. .exe files can store applications, games, installers, or malware. They can be launched from the command line or via the GUI by double-clicking. .exe files are system-dependent - they store data in binary format, and their internal signature determines the executable sub-type.
Every .exe starts with the two-byte magic signature MZ (hex 4D 5A) at offset 0, named after its co-designer Mark Zbikowski. Modern Windows executables additionally carry a PE\0\0 signature at the offset stored at position 0x3C, confirming the file as a Portable Executable. There are five main historical .exe sub-formats:
MZ- 16-bit format native to DOS.NE- 16-bit "New Executable" format used by 16-bit Windows (1.x-3.x) and OS/2 1.x; cannot run on bare DOS, but is supported by 32-bit Windows compatibility layers and OS/2.LX- 32-bit format for OS/2 2.0 and later.LE- 16/32-bit format mainly used for VxD drivers in older Windows systems (those released before year 2000).PE- "Portable Executable", covering both 32-bit (PE32) and 64-bit (PE32+) versions; introduced with Windows NT and the dominant format today. ARM and ARM64 variants extend PE for Windows on ARM devices.
.exe files can store resources such as icons, dialogs, version information, audio, and application manifests. It is important to remember that not all types of .exe files can be executed on a given system, as such files are platform-dependent. To run an .exe on a different operating system, an appropriate emulation tool such as Wine or CrossOver is required. Self-extracting archives also use the .exe extension, beginning with an MZ/PE stub and carrying a ZIP archive, 7z, or CAB payload internally.
Modern Windows .exe files commonly carry an Authenticode code signature to verify publisher identity, and the OS enforces security features including ASLR, DEP/NX, and Control Flow Guard. Imports from .dll files are resolved at load time by the Windows PE loader. .exe files from unknown or untrusted sources must be handled with care, because they carry a risk of malware infection if executed.
Security & safety
RISK: HIGHEXE is the #1 malware vector on Windows: it can run any code with your privileges, so viruses, trojans, ransomware and 'cracks/keygens' are typically EXE files. Safety checklist: only run EXEs from the official vendor or a trusted store; before running, check the digital signature (right-click → Properties → Digital Signatures) - legitimate software is code- signed and the publisher name matches; be very suspicious of EXEs arriving by e-mail, chat, or bundled with 'free' downloads. Windows SmartScreen and antivirus warnings on an unrecognized EXE should be taken seriously. To inspect a download without executing it, open it as an archive in 7-Zip, or scan it on VirusTotal. Watch for double extensions like 'invoice.pdf.exe' and EXEs disguised with document icons.
Format details
in a nutshellPrograms that open EXE files
Technical details
deep spec| Magic bytes | MZ (4D 5A) at offset 0; the PE signature PE\0\0 (50 45 00 00) appears at the offset stored in the MZ stub at 0x3C |
| MIME type | application/vnd.microsoft.portable-executable |
| Architecture support | x86 (32-bit), x86-64/AMD64 (64-bit), ARM, ARM64; the target machine is encoded in the COFF File Header Machine field |
| Sub-format variants | MZ (MS-DOS 16-bit), NE (16-bit Windows/OS/2 1.x), LX (OS/2 2.x 32-bit), LE (VxD drivers), PE32 (32-bit Windows), PE32+ (64-bit Windows) |
| PE section layout | Sections include .text (executable code), .data (initialized data), .rdata (read-only data), .rsrc (resources), and .reloc (base relocations) |
| Entry point | Relative virtual address (RVA) of the first instruction, stored in AddressOfEntryPoint in the PE Optional Header |
| Import table | Lists the DLLs and named or ordinal function exports the binary requires; resolved by the Windows loader at startup |
| Export table | Optionally exposes functions or data symbols for use by other executables or DLLs; present mainly in DLLs but occasionally in EXEs |
| Resource section (.rsrc) | Embeds icons, bitmaps, dialogs, string tables, version information, and application manifests in a typed/named/language-tagged tree |
| Code signing | Authenticode (PKCS#7/CMS) digital signature stored in the Security Directory; validated by Windows SmartScreen, UAC, and the kernel at driver load time |
| Security mitigations | DllCharacteristics flags in the Optional Header enable ASLR, DEP/NX, Control Flow Guard (CFG), SafeSEH, and High-Entropy VA for 64-bit binaries |
| PE checksum | Four-byte CheckSum field in the Optional Header; enforced by the Windows loader for kernel-mode drivers and system files |
| Subsystem types | Windows GUI, Windows console (CUI), native (kernel-mode), EFI application, EFI boot service driver, EFI runtime driver |
| Self-extracting archive use | SFX packages embed a ZIP, 7z, or CAB payload after the PE stub; the file runs as a normal executable and unpacks automatically |
| Released | 1985 (MS-DOS MZ); PE format since Windows NT 3.1, 1993 |
| Specification | learn.microsoft.com |