CVE-2017-15742 describes a denial-of-service vulnerability in IrfanView 4.50 (64-bit) when using the CADImage plugin version 12.0.0.5. A specially crafted .dwg file can trigger a read access violation, leading to a crash and potential unspecified further impact. With a CVSS score of 7.8 (High), this vulnerability requires user interaction (opening the malicious file) and has high impacts on confidentiality, integrity, and availability. There is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.50CPE matchmatch criteria | cpe:2.3:a:irfanview:irfanview:4.50:*:*:*:*:x64:*:* | ||
12.0.0.5CPE matchmatch criteria | cpe:2.3:a:irfanview:cadimage:12.0.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.