Memory Corruption Vulnerability in IrfanView CADImage Plugin
CVE-2025-7309

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7309?

The IrfanView CADImage Plugin contains a vulnerability that stems from inadequate validation of user-supplied data during DWG file parsing. This flaw can lead to a memory corruption condition, allowing remote attackers to execute arbitrary code on compromised installations. To exploit this vulnerability, a user must interact with a malicious web page or open a harmful file. Safeguarding against this risk involves updating the plugin to the latest version as well as employing security best practices to minimize exposure.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.