Memory Corruption Vulnerability in IrfanView CADImage Plugin Allows Remote Code Execution
CVE-2025-7277

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7277?

The vulnerability in the IrfanView CADImage Plugin arises from improper validation during the parsing of DWG files. This security flaw can be exploited by remote attackers to execute arbitrary code on affected systems, requiring user interaction to trigger the attack. Users must visit a malicious webpage or open a compromised file for the exploitation to occur, leading to potential unauthorized actions in the context of the affected application.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7277 : Memory Corruption Vulnerability in IrfanView CADImage Plugin Allows Remote Code Execution