Remote Code Execution Risk in IrfanView CADImage Plugin
CVE-2025-7321

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7321?

A vulnerability in the IrfanView CADImage Plugin relates to the mishandling of DWG file parsing leading to memory corruption. By exploiting this flaw, attackers may execute arbitrary code on victims' systems, contingent upon user interaction such as visiting a compromised webpage or opening a malicious file. The issue arises from insufficient validation of user-provided input, which compromises application integrity.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7321 : Remote Code Execution Risk in IrfanView CADImage Plugin