CVE-2025-7252 is an out-of-bounds read vulnerability in the IrfanView CADImage Plugin, specifically affecting its DWG file parsing. This flaw allows remote attackers to execute arbitrary code on affected IrfanView installations, including products from cadsofttools. Exploitation requires user interaction, such as opening a malicious DWG file or visiting a malicious webpage. Rated with a CVSS score of 7.8 (High), the vulnerability has a low attack complexity but high impact on confidentiality, integrity, and availability. The issue stems from insufficient validation of user-supplied data, leading to a read past the end of an allocated buffer. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Despite its high severity, it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.0.0.8CPE matchmatch criteria | cpe:2.3:a:cadsofttools:cadimage:*:*:*:*:*:irfanview:x64:* | ||
< 15.0.0.8CPE matchmatch criteria | cpe:2.3:a:cadsofttools:cadimage:*:*:*:*:*:irfanview:x86:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.