Impact
An out-of-bounds read vulnerability in Canva Affinity’s EMF processing allows an attacker to read beyond the intended bounds of a memory buffer when opening a specially crafted EMF file. This can expose sensitive data that resides adjacent in memory, potentially revealing confidential information to the attacker. The weakness is classified as CWE-125: Out-Of-Bounds Read.
Affected Systems
The vulnerability affects the Canva Affinity product on Windows platforms as identified by the CPE string cpe:2.3:a:canva:affinity:*:*:*:*:*:windows:*. No specific affected version information is provided in the available data, so all deployed versions of Canva Affinity that process EMF files are potentially impacted.
Risk and Exploitability
The CVSS score is 6.1, indicating moderate severity. The EPSS score is reported as below 1%, suggesting a low probability of immediate exploitation in the wild, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector involves delivering or executing a malicious EMF file on the targeted system, possibly requiring the user to open the file, which implies a local or user‑initiated remote vector. No evidence of remote code execution or privilege escalation is stated. The risk is therefore primarily confidentiality‑related at the local system level, with exploitation likely limited to environments where untrusted EMF files can be opened.
OpenCVE Enrichment