Memory Corruption Vulnerability in IrfanView CADImage Plugin
CVE-2025-7255

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7255?

The IrfanView CADImage Plugin is vulnerable to a memory corruption flaw that affects the parsing of DWG files. This vulnerability can be exploited by remote attackers to execute arbitrary code by leveraging user-supplied data that is poorly validated. Specifically, users may inadvertently trigger this flaw by opening a malicious DWG file or visiting a compromised webpage containing such a file. Successful exploitation allows an attacker to execute code within the context of the affected process, posing significant risks to the system's integrity and security.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7255 : Memory Corruption Vulnerability in IrfanView CADImage Plugin