Memory Corruption Vulnerability in IrfanView CADImage Plugin
CVE-2025-7308

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7308?

The IrfanView CADImage Plugin contains a vulnerability in its DWG file parsing functionality, which can lead to memory corruption and allow remote attackers to execute arbitrary code on affected installations. This vulnerability requires user interaction, as exploitation necessitates that an unsuspecting user opens a specially crafted DWG file or visits a malicious website. The flaw arises from inadequate validation of user-supplied data, potentially enabling attackers to run code within the context of the current process, posing significant security risks.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7308 : Memory Corruption Vulnerability in IrfanView CADImage Plugin