PT-2025-28677 · Irfanview · Irfanview+1

Rocco Calvi

+1

·

Published

2025-02-11

·

Updated

2025-07-28

·

CVE-2025-7246

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IrfanView CADImage Plugin (affected versions not specified)
Description This issue involves a memory corruption vulnerability in the DWG file parsing functionality of the IrfanView CADImage Plugin. Successful exploitation allows remote attackers to execute arbitrary code within the context of the current process. User interaction is required, specifically the need for a target to visit a malicious page or open a malicious file. The root cause is inadequate validation of user-supplied data during DWG file parsing, leading to a memory corruption condition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-08344
CVE-2025-7246
ZDI-25-498

Affected Products

Cadimage Plugin
Irfanview