IrfanView CADImage Plugin File Parsing Issue Exposes Sensitive Data
CVE-2025-7233
What is CVE-2025-7233?
The IrfanView CADImage Plugin contains a vulnerability that arises during the parsing of DWG files, leading to the potential exposure of sensitive information. This flaw is due to inadequate validation of user-supplied data, enabling an attacker to manipulate how data is processed. To exploit this vulnerability, an attacker must convince the victim to visit a crafted webpage or open a malicious DWG file. If successfully exploited, this could allow the attacker to read beyond the allocated buffer, potentially exposing confidential data stored on the system. Users are advised to implement cautious practices and evaluate the severity of their installations to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
IrfanView 4.70.0.0
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
