IrfanView CADImage Plugin File Parsing Issue Exposes Sensitive Data
CVE-2025-7233

3.3LOW

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7233?

The IrfanView CADImage Plugin contains a vulnerability that arises during the parsing of DWG files, leading to the potential exposure of sensitive information. This flaw is due to inadequate validation of user-supplied data, enabling an attacker to manipulate how data is processed. To exploit this vulnerability, an attacker must convince the victim to visit a crafted webpage or open a malicious DWG file. If successfully exploited, this could allow the attacker to read beyond the allocated buffer, potentially exposing confidential data stored on the system. Users are advised to implement cautious practices and evaluate the severity of their installations to mitigate risks.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7233 : IrfanView CADImage Plugin File Parsing Issue Exposes Sensitive Data