Memory Corruption Flaw in IrfanView CADImage Plugin DXF File Handling
CVE-2025-7325

7.8HIGH

Key Information:

Vendor

Irfanview

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-7325?

The IrfanView CADImage Plugin exhibits a memory corruption vulnerability due to inadequate validation of user-supplied DXF file data. This flaw enables remote attackers to execute arbitrary code on the affected installations, provided they can entice a user to open a malicious DXF file or visit a compromised webpage. The exploitation of this vulnerability hinges on creating specific conditions that lead to memory corruption, ultimately allowing attackers to execute unauthorized code within the context of the current process.

Affected Version(s)

IrfanView 4.70.0.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7325 : Memory Corruption Flaw in IrfanView CADImage Plugin DXF File Handling