Remote Code Execution Vulnerability in IrfanView CADImage Plugin
CVE-2025-7302

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7302?

A vulnerability exists in the IrfanView CADImage Plugin caused by inadequate validation of user-supplied data during DWG file parsing. This flaw can lead to memory corruption, allowing remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, as targets must either visit a malicious webpage or open a compromised file. Once triggered, the attacker can execute code within the context of the affected process, potentially leading to full system compromise.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7302 : Remote Code Execution Vulnerability in IrfanView CADImage Plugin