Remote Code Execution Vulnerability in IrfanView CADImage Plugin
CVE-2025-7275
7.8HIGH
What is CVE-2025-7275?
The IrfanView CADImage Plugin is susceptible to a remote code execution vulnerability that arises from improper parsing of CGM files. Attackers can exploit this flaw to execute arbitrary code on affected systems. This occurs primarily due to the lack of adequate validation of user-supplied data during file processing. Exploitation requires user interaction; the target must either visit a malicious webpage or open a specially crafted CGM file. This oversight can lead to severe security implications for users.
Affected Version(s)
IrfanView 4.70.0.0