Memory Corruption Vulnerability in IrfanView CADImage Plugin
CVE-2025-7289
7.8HIGH
What is CVE-2025-7289?
A memory corruption vulnerability in the IrfanView CADImage Plugin occurs due to improper validation when parsing DXF files. This flaw allows remote attackers to execute arbitrary code on the affected installations. To exploit this vulnerability, user interaction is required; the user must either visit a malicious webpage or open a specially crafted DXF file. By leveraging this weakness, an attacker can gain control over the affected system’s current process, potentially leading to unauthorized access and data breaches.
Affected Version(s)
IrfanView 4.70.0.0