Multiple memory corruption vulnerabilities in IrfanView CADImage plugin affecting CGM, DXF, and DWG file parsing. All 139 vulnerabilities have CVSS 7....
Description
Multiple memory corruption vulnerabilities in IrfanView CADImage plugin affecting CGM, DXF, and DWG file parsing. All 139 vulnerabilities have CVSS 7.8 and allow remote code execution via malicious CAD files.
AI Analyst Comment
Remediation
Apply IrfanView security patches immediately. Consider disabling CADImage plugin if CAD file support not required.
Executive Summary:
Multiple IrfanView CADImage plugin vulnerabilities affecting CAD file parsing (CGM, DXF, DWG formats). All 139 vulnerabilities allow remote code execution via malicious files.
Vulnerability Details
CVE Range: CVE-2025-7234, CVE-2025-7235, CVE-2025-7235 (and 136 others)
Affected Software: IrfanView CADImage Plugin
Vulnerability: Memory corruption flaws (out-of-bounds writes, buffer overflows) in CAD file parsing routines. Malicious CAD files can trigger arbitrary code execution.
Business Impact
High severity (CVSS 7.8) with potential for complete system compromise. The volume of vulnerabilities indicates systemic plugin security issues.
Remediation Plan
Apply IrfanView security patches immediately. If CAD support not required, disable CADImage plugin (CADImage.dll).
Exploitation Status
No public exploits available as of July 21, 2025.
Analyst Recommendation
The high volume of related vulnerabilities (139 CVEs) represents significant security debt. Prioritize patching or disable plugin if not business-critical.