CVE-2025-66342

7.8

Canva · Affinity

A type confusion vulnerability in Canva Affinity allows attackers to trigger memory corruption and achieve arbitrary code execution via a specially crafted EMF file.

Executive summary

A critical type confusion vulnerability in Canva Affinity can lead to arbitrary code execution if a user opens a malicious EMF file.

Vulnerability

The software contains a type confusion flaw (CWE-843) within its EMF file parsing functionality. Exploitation requires no authentication but relies on user interaction, as an attacker must convince a victim to open a specially crafted EMF file.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity due to the potential for total system compromise. Successful exploitation grants an attacker the ability to execute arbitrary code, which may result in full system control, unauthorized data access, or the deployment of persistent malware within the enterprise environment.

Remediation

Immediate Action: Update Canva Affinity to the latest version provided by the vendor to remediate the vulnerable EMF parsing logic.

Proactive Monitoring: Monitor file access patterns and endpoint activity for unusual processes spawned by the Affinity application when handling image files.

Compensating Controls: Implement endpoint protection solutions that scan incoming files for malformed headers or known malicious patterns before they are processed by graphics software.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability poses a significant risk to workstations utilizing Canva Affinity. Administrators should prioritize identifying instances of version 3.0.1.3808 and ensure all affected systems are updated immediately. Until patches are applied, users should be advised to exercise caution when opening EMF files from untrusted sources.

Sources

Originally found and disclosed by Discovered by KPC of Cisco Talos., per the CVE Program record.