Glossary
MZ header (MS-DOS header)
The 64-byte header at the start of every PE file, beginning with the letters MZ, whose e_lfanew field points to the PE header.
Every Windows executable begins with a 64-byte MS-DOS header whose first two bytes are MZ (0x4D 0x5A). Most of its fields only mattered for MS-DOS; the one that matters today is e_lfanew at offset 0x3C, the file offset of the PE\0\0 signature.
Between the header and the PE signature sits the DOS stub — the program that prints "This program cannot be run in DOS mode." — and, in files linked by Microsoft tools, the Rich header. An MZ file without a valid PE signature is a DOS program or a damaged file. Tools such as the PE Parser recognise executables by this magic number rather than by extension, so renamed payloads are still found.