Remote Code Execution Vulnerability in IrfanView CADImage Plugin
CVE-2025-7256

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7256?

The IrfanView CADImage Plugin has a vulnerability that arises from improper validation during the parsing of DXF files. This flaw can lead to memory corruption, allowing remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, as the target must either open a malicious file or visit a compromised webpage that triggers the vulnerability. Effective mitigation measures and prompt updates to the plugin are recommended to safeguard against potential exploits.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7256 : Remote Code Execution Vulnerability in IrfanView CADImage Plugin