Memory Corruption Vulnerability in IrfanView CADImage Plugin
CVE-2025-7308
7.8HIGH
What is CVE-2025-7308?
The IrfanView CADImage Plugin contains a vulnerability in its DWG file parsing functionality, which can lead to memory corruption and allow remote attackers to execute arbitrary code on affected installations. This vulnerability requires user interaction, as exploitation necessitates that an unsuspecting user opens a specially crafted DWG file or visits a malicious website. The flaw arises from inadequate validation of user-supplied data, potentially enabling attackers to run code within the context of the current process, posing significant security risks.
Affected Version(s)
IrfanView 4.70.0.0