Remote Code Execution Flaw in IrfanView CADImage Plugin Due to DXF File Parsing
CVE-2025-7267
7.8HIGH
What is CVE-2025-7267?
The IrfanView CADImage Plugin contains a vulnerability stemming from inadequate validation processes when parsing DXF files. This can lead to an out-of-bounds read, which offers a potential path for remote attackers to execute arbitrary code on targeted systems. Exploiting this flaw requires user interaction, as victims must either open a malicious DXF file or visit a compromised webpage that utilizes this file type. Proper safeguards against malformed data are essential to prevent unauthorized access and maintain system integrity.
Affected Version(s)
IrfanView 4.70.0.0