Remote Code Execution Vulnerability in IrfanView CADImage Plugin
CVE-2025-7276
7.8HIGH
What is CVE-2025-7276?
The IrfanView CADImage Plugin contains a vulnerability in the way it parses DXF files, which makes it susceptible to memory corruption. This flaw arises from the lack of adequate validation of user-supplied data. Attackers can exploit this vulnerability by convincing users to visit a malicious webpage or open a compromised DXF file, allowing them to execute arbitrary code in the context of the application. Users are urged to ensure their systems are secure by applying updates and following best practices to mitigate exploitation.
Affected Version(s)
IrfanView 4.70.0.0