CVE-2025-64301
7.8Canva · Affinity
A critical out-of-bounds write vulnerability in Canva Affinity allows attackers to execute arbitrary code through a specially crafted EMF file.
Executive summary
Canva Affinity version 3.0.1.3808 is susceptible to an out-of-bounds write vulnerability that could permit remote code execution via malicious EMF file processing.
Vulnerability
This vulnerability, identified as CWE-787, occurs within the Enhanced Metafile (EMF) processing functionality of the software. An attacker can trigger this flaw by enticing a user to open a specially crafted EMF file, which requires no prior authentication to initiate the exploit process.
Business impact
The potential for arbitrary code execution poses a severe threat to system integrity and confidentiality. A successful exploit could allow an attacker to gain full control over the affected workstation, leading to unauthorized data access, the deployment of malware, or complete system compromise. Given the CVSS score of 7.8, this vulnerability represents a high-risk entry point that requires immediate attention to prevent potential lateral movement within the network.
Remediation
Immediate Action: Users should immediately transition to a secure version of the software as soon as the vendor releases a patch, while avoiding the opening of untrusted or suspicious EMF files in the interim.
Proactive Monitoring: Security teams should monitor endpoint activity for unexpected child processes spawned by the Affinity application and review logs for unusual file handling errors associated with EMF parsing.
Compensating Controls: Deploying endpoint protection solutions that perform deep inspection of file formats and restricting the execution of files from untrusted sources can help mitigate the risk while awaiting a formal vendor update.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution, this vulnerability should be treated with high priority. Organizations utilizing Canva Affinity 3.0.1.3808 must track the vendor security portal for the immediate release of a patch and apply it across all workstations as soon as it becomes available. In the meantime, instruct end-users to exercise caution when handling EMF files from external or unverified sources.
Sources
Originally found and disclosed by Discovered by KPC of Cisco Talos., per the CVE Program record.