IrfanView CADImage Plugin File Parsing Issue Exposes Sensitive Data
CVE-2025-7233
3.3LOW
What is CVE-2025-7233?
The IrfanView CADImage Plugin contains a vulnerability that arises during the parsing of DWG files, leading to the potential exposure of sensitive information. This flaw is due to inadequate validation of user-supplied data, enabling an attacker to manipulate how data is processed. To exploit this vulnerability, an attacker must convince the victim to visit a crafted webpage or open a malicious DWG file. If successfully exploited, this could allow the attacker to read beyond the allocated buffer, potentially exposing confidential data stored on the system. Users are advised to implement cautious practices and evaluate the severity of their installations to mitigate risks.
Affected Version(s)
IrfanView 4.70.0.0