Memory Corruption Vulnerability in IrfanView CADImage Plugin
CVE-2025-7290
7.8HIGH
What is CVE-2025-7290?
The IrfanView CADImage Plugin contains a memory corruption vulnerability specifically tied to the parsing of DXF files. This security flaw arises from improper validation of user-supplied data, enabling remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious site or opening a compromised file. This vulnerability could lead to severe security implications for users, emphasizing the importance of prompt updates and caution when handling DXF files.
Affected Version(s)
IrfanView 4.70.0.0