Remote Code Execution Vulnerability in IrfanView CADImage Plugin
CVE-2025-7302
7.8HIGH
What is CVE-2025-7302?
A vulnerability exists in the IrfanView CADImage Plugin caused by inadequate validation of user-supplied data during DWG file parsing. This flaw can lead to memory corruption, allowing remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, as targets must either visit a malicious webpage or open a compromised file. Once triggered, the attacker can execute code within the context of the affected process, potentially leading to full system compromise.
Affected Version(s)
IrfanView 4.70.0.0