Memory Corruption in IrfanView CADImage Plugin Leading to Remote Code Execution
CVE-2025-7270

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7270?

The IrfanView CADImage Plugin has a vulnerability in the way it handles the parsing of DWG files, leading to potential memory corruption. This flaw arises from insufficient validation of user-supplied data, allowing remote attackers to execute arbitrary code on affected systems. User interaction is necessary, as the victim must either visit a malicious web page or open a compromised file to trigger the exploit. When exploited, this vulnerability could allow attackers to execute code within the context of the application, posing serious risks to user data and system integrity.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7270 : Memory Corruption in IrfanView CADImage Plugin Leading to Remote Code Execution