Remote Code Execution Vulnerability in IrfanView CADImage Plugin
CVE-2025-7246

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7246?

The IrfanView CADImage Plugin is susceptible to a specific vulnerability during the parsing of DWG files. This flaw arises from inadequate validation of user-supplied data, leading to memory corruption. Successful exploitation requires user interaction; an attacker must entice the user to open a malicious file or visit a compromised webpage. This breach enables the attacker to execute arbitrary code within the context of the affected process, posing significant security risks to users.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7246 : Remote Code Execution Vulnerability in IrfanView CADImage Plugin