IrfanView CADImage Plugin File Parsing Issue Exposes Sensitive Data
CVE-2025-7233

5.5MEDIUM

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7233?

The IrfanView CADImage Plugin contains a vulnerability that arises during the parsing of DWG files, leading to the potential exposure of sensitive information. This flaw is due to inadequate validation of user-supplied data, enabling an attacker to manipulate how data is processed. To exploit this vulnerability, an attacker must convince the victim to visit a crafted webpage or open a malicious DWG file. If successfully exploited, this could allow the attacker to read beyond the allocated buffer, potentially exposing confidential data stored on the system. Users are advised to implement cautious practices and evaluate the severity of their installations to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.