Remote Code Execution Flaw in IrfanView CADImage Plugin Due to DXF File Parsing
CVE-2025-7267

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7267?

The IrfanView CADImage Plugin contains a vulnerability stemming from inadequate validation processes when parsing DXF files. This can lead to an out-of-bounds read, which offers a potential path for remote attackers to execute arbitrary code on targeted systems. Exploiting this flaw requires user interaction, as victims must either open a malicious DXF file or visit a compromised webpage that utilizes this file type. Proper safeguards against malformed data are essential to prevent unauthorized access and maintain system integrity.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7267 : Remote Code Execution Flaw in IrfanView CADImage Plugin Due to DXF File Parsing