Remote Code Execution Vulnerability in IrfanView CADImage Plugin
CVE-2025-7256
7.8HIGH
What is CVE-2025-7256?
The IrfanView CADImage Plugin has a vulnerability that arises from improper validation during the parsing of DXF files. This flaw can lead to memory corruption, allowing remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, as the target must either open a malicious file or visit a compromised webpage that triggers the vulnerability. Effective mitigation measures and prompt updates to the plugin are recommended to safeguard against potential exploits.
Affected Version(s)
IrfanView 4.70.0.0