CRITICAL🇵🇱 Wersja polska

CVE-2026-23751

CVSS 9.3v4.0pub. 2026-04-23upd. 2026-04-24

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling techniques to instantiate a remote System.Net.WebClient object and read arbitrary files from the server filesystem, write attacker-controlled files to the server, or coerce NTLMv2 authentication to an attacker-controlled host, enabling sensitive credential disclosure, denial of service, remote code execution, or lateral movement depending on service account privileges and network environment.

🤖 AI Analysis
How it works

The Ascent Capture Service exposes a .NET Remoting HTTP channel on port 2424 using a default, publicly known endpoint identifier and without any authentication mechanism. An attacker can exploit .NET Remoting object deserialization techniques to remotely instantiate objects such as System.Net.WebClient. This allows reading arbitrary files from the server file system, writing attacker-controlled files, or forcing NTLMv2 authentication coercion against a host controlled by the attacker.

Impact

An attacker can gain unauthorized access to server files, execute remote code (RCE), cause denial of service (DoS), intercept NTLMv2 credentials, or perform lateral movement – the scope of impact depends on service account permissions and network configuration.

Mitigation & patch

Apply patches available from the vendor according to references (Tungsten Automation documentation: https://docshield.tungstenautomation.com). Additionally, it is recommended to restrict network access to port 2424 exclusively to trusted hosts (firewall/network segmentation) and disable the .NET Remoting HTTP channel if not required for system operation.

Who is affected

Kofax Capture / Tungsten Capture version 6.0.0.0; other versions may also be vulnerable according to vendor description.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDoS
CWE
References