Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling techniques to instantiate a remote System.Net.WebClient object and read arbitrary files from the server filesystem, write attacker-controlled files to the server, or coerce NTLMv2 authentication to an attacker-controlled host, enabling sensitive credential disclosure, denial of service, remote code execution, or lateral movement depending on service account privileges and network environment.
The Ascent Capture Service exposes a .NET Remoting HTTP channel on port 2424 using a default, publicly known endpoint identifier and without any authentication mechanism. An attacker can exploit .NET Remoting object deserialization techniques to remotely instantiate objects such as System.Net.WebClient. This allows reading arbitrary files from the server file system, writing attacker-controlled files, or forcing NTLMv2 authentication coercion against a host controlled by the attacker.
An attacker can gain unauthorized access to server files, execute remote code (RCE), cause denial of service (DoS), intercept NTLMv2 credentials, or perform lateral movement – the scope of impact depends on service account permissions and network configuration.
Apply patches available from the vendor according to references (Tungsten Automation documentation: https://docshield.tungstenautomation.com). Additionally, it is recommended to restrict network access to port 2424 exclusively to trusted hosts (firewall/network segmentation) and disable the .NET Remoting HTTP channel if not required for system operation.
Kofax Capture / Tungsten Capture version 6.0.0.0; other versions may also be vulnerable according to vendor description.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X