CVE-2025-7324 is an out-of-bounds read vulnerability in the IrfanView CADImage Plugin, specifically affecting its DXF file parsing. This flaw allows remote attackers to execute arbitrary code on affected IrfanView installations, including products from CadSoftTools. Exploitation requires user interaction, such as opening a malicious DXF file or visiting a malicious webpage. Rated with a CVSS score of 7.8 (High), this vulnerability has a low attack complexity but high impact on confidentiality, integrity, and availability, as it can lead to arbitrary code execution. The EPSS score is very low, indicating a minimal probability of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.0.8CPE matchmatch criteria | cpe:2.3:a:cadsofttools:cadimage:*:*:*:*:*:irfanview:x64:* | ||
< 15.0.0.8CPE matchmatch criteria | cpe:2.3:a:cadsofttools:cadimage:*:*:*:*:*:irfanview:x86:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.