Memory Corruption Vulnerability in IrfanView CADImage Plugin Allows Remote Code Execution
CVE-2025-7277
7.8HIGH
What is CVE-2025-7277?
The vulnerability in the IrfanView CADImage Plugin arises from improper validation during the parsing of DWG files. This security flaw can be exploited by remote attackers to execute arbitrary code on affected systems, requiring user interaction to trigger the attack. Users must visit a malicious webpage or open a compromised file for the exploitation to occur, leading to potential unauthorized actions in the context of the affected application.
Affected Version(s)
IrfanView 4.70.0.0