CVE-2025-7325 is a memory corruption vulnerability in the IrfanView CADImage Plugin, affecting IrfanView and CADSoftTools products, specifically when parsing malicious DXF files. This high-severity flaw (CVSS 7.8) allows remote code execution with user interaction, requiring the target to open a specially crafted file or visit a malicious page. While no public exploits, Metasploit modules, or social media discussions are currently identified, its potential for complete compromise of confidentiality, integrity, and availability makes it a significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.0.8CPE matchmatch criteria | cpe:2.3:a:cadsofttools:cadimage:*:*:*:*:*:irfanview:x64:* | ||
< 15.0.0.8CPE matchmatch criteria | cpe:2.3:a:cadsofttools:cadimage:*:*:*:*:*:irfanview:x86:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.