CVE-2025-61952: High severity Canva Affinity vulnerability
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61952?
CVE-2025-61952 is classified as a medium-severity vulnerability due to its potential for disclosing sensitive information.
How do I fix CVE-2025-61952?
To mitigate CVE-2025-61952, users should update Canva Affinity to the latest version that addresses this vulnerability.
What type of attack does CVE-2025-61952 facilitate?
CVE-2025-61952 allows for an attacker to perform an out-of-bounds read, potentially leading to the exposure of sensitive data.
Which software versions are affected by CVE-2025-61952?
CVE-2025-61952 affects Canva Affinity versions up to 3.1.0 on Windows.
Is it possible to exploit CVE-2025-61952 remotely?
Yes, CVE-2025-61952 can be exploited by using specially crafted EMF files, which may be sent via various attack vectors.