Memory Corruption Issue in IrfanView CADImage Plugin Allowing Code Execution
CVE-2025-7254

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7254?

A vulnerability within the IrfanView CADImage Plugin arises from improper validation during the parsing of DXF files. This flaw can lead to memory corruption conditions, enabling remote attackers to execute arbitrary code if a user inadvertently visits a malicious webpage or opens a compromised file. The risk emphasizes the importance of cautious file handling and keeping plugins updated to mitigate potential exploits.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7254 : Memory Corruption Issue in IrfanView CADImage Plugin Allowing Code Execution