Memory Corruption Vulnerability in IrfanView CADImage Plugin
CVE-2025-7272
7.8HIGH
What is CVE-2025-7272?
The IrfanView CADImage Plugin is vulnerable to remote code execution due to improper validation while parsing DXF files. Attackers can exploit this weakness by tricking users into opening malicious files or visiting harmful links, leading to memory corruption. When successful, the attacker can execute arbitrary code within the context of the affected process, potentially compromising system integrity and confidentiality.
Affected Version(s)
IrfanView 4.70.0.0