Memory Corruption Issue in IrfanView CADImage Plugin Allowing Code Execution
CVE-2025-7254

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7254?

A vulnerability within the IrfanView CADImage Plugin arises from improper validation during the parsing of DXF files. This flaw can lead to memory corruption conditions, enabling remote attackers to execute arbitrary code if a user inadvertently visits a malicious webpage or opens a compromised file. The risk emphasizes the importance of cautious file handling and keeping plugins updated to mitigate potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.