Memory Corruption and Remote Code Execution in IrfanView CADImage Plugin
CVE-2025-7244
7.8HIGH
What is CVE-2025-7244?
The IrfanView CADImage Plugin has a vulnerability that allows remote code execution due to improper validation of DWG files during parsing. An attacker must trick a user into opening a malicious file or visiting a compromised webpage to exploit this flaw. If successful, the attacker could execute arbitrary code within the context of the affected process, resulting in potential unauthorized actions and system compromise.
Affected Version(s)
IrfanView 4.70.0.0