CVE-2025-64301: High severity Canva Affinity vulnerability
An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out‑of‑bounds write, potentially leading to code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64301?
CVE-2025-64301 is considered a critical vulnerability due to its potential for code execution.
How do I fix CVE-2025-64301?
To fix CVE-2025-64301, ensure that you update Canva Affinity to the latest version that addresses this vulnerability.
What is the impact of CVE-2025-64301?
The impact of CVE-2025-64301 includes the possibility of an attacker gaining control of the affected system through an out-of-bounds write.
Which software is affected by CVE-2025-64301?
CVE-2025-64301 affects Canva Affinity, particularly its EMF functionality.
Can CVE-2025-64301 be exploited remotely?
Yes, CVE-2025-64301 can be exploited remotely if an attacker sends a specially crafted EMF file to the user.