CVE-2025-66042: High severity Canva Affinity vulnerability
An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66042?
CVE-2025-66042 has a high severity rating due to its potential to disclose sensitive information through an out-of-bounds read.
How do I fix CVE-2025-66042?
To address CVE-2025-66042, ensure that you are using an updated version of Canva Affinity beyond version 3.1.0 where the vulnerability is mitigated.
What type of vulnerability is CVE-2025-66042?
CVE-2025-66042 is classified as an out-of-bounds read vulnerability specifically within the EMF functionality of Canva Affinity.
Which software is impacted by CVE-2025-66042?
CVE-2025-66042 affects Canva Affinity, particularly versions up to 3.1.0 on Windows.
What can an attacker achieve by exploiting CVE-2025-66042?
An attacker exploiting CVE-2025-66042 could potentially gain access to sensitive information by using a specially crafted EMF file.