Out-Of-Bounds Read Vulnerability in IrfanView CADImage Plugin
CVE-2025-7319
7.8HIGH
What is CVE-2025-7319?
The IrfanView CADImage Plugin contains a vulnerability that arises during the parsing of DWG files. Due to improper validation of user-supplied data, an out-of-bounds read can occur, allowing an attacker to execute arbitrary code on the affected system. To exploit this issue, user interaction is required, as the victim must either visit a malicious webpage or open a specially crafted DWG file. This poses a significant threat, enabling potential remote code execution in the current process context, emphasizing the importance of updating and securing affected installations.
Affected Version(s)
IrfanView 4.70.0.0