Impact
Key detail from CVE description: an out‑of‑bounds read vulnerability exists in the Enhanced Metafile (EMF) processing component of Canva Affinity. By supplying a specially crafted EMF file, an attacker can cause the application to read memory beyond the intended bounds, potentially exposing sensitive data stored in that memory. The weakness is identified as CWE‑125 (Out‑Of‑Bounds Read).
Affected Systems
The impacted software is Canva Affinity, with no specific affected version listed by the CNA. The issue is present for all Windows deployments of the product that include the default EMF functionality, as indicated by the CPE string. Users running any release that has not been updated against this vulnerability are potentially affected.
Risk and Exploitability
The CVSS base score of 6.1 classifies the vulnerability as moderate severity. The EPSS score of less than 1% implies a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker must supply a malicious EMF file – which could be introduced locally (e.g., via a file opened by a user) or remotely if EMF files are distributed through shared media or email attachments. The limited exploitability suggests that further defensive controls may mitigate the threat.
OpenCVE Enrichment