Impact
The vulnerability is an out-of-bounds read that occurs when the Affinity application processes EMF files. An attacker who supplies a specially crafted EMF file can trigger the overflow and read memory that may contain sensitive data, exposing confidential information. The weakness corresponds to CWE-125, indicating an out-of-bounds read that can lead to information disclosure.
Affected Systems
Affects Canva's Affinity product running on Windows platforms. No specific product versions are listed in the CVE data, but the CPE identifier cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*:* indicates all versions of Affinity on Windows could be impacted.
Risk and Exploitability
The CVSS score of 6.1 classifies the issue as moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Although the official attacker’s path is not explicitly described, the description implies that the attack vector requires an attacker to supply a malicious EMF file, which could be delivered via email, web download, or local file import. This inference indicates that the vulnerability is primarily exploitable through local or remote file inclusion when the application allows EMF files from arbitrary sources.
OpenCVE Enrichment