Remote Code Execution Vulnerability in IrfanView CADImage Plugin for DWG Files
CVE-2025-7262

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7262?

The IrfanView CADImage Plugin contains a vulnerability in its handling of DWG file parsing that could allow remote attackers to execute arbitrary code. This flaw arises from inadequate validation of user-supplied data, leading to potential reads beyond allocated buffers. To exploit this vulnerability, an attacker must trick a user into visiting a malicious webpage or opening a compromised file. When successfully exploited, the attacker can execute code within the context of the user’s current session, posing significant risks to system security.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7262 : Remote Code Execution Vulnerability in IrfanView CADImage Plugin for DWG Files