CVE-2026-23751: Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting
Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling techniques to instantiate a remote System.Net.WebClient object and read arbitrary files from the server filesystem, write attacker-controlled files to the server, or coerce NTLMv2 authentication to an attacker-controlled host, enabling sensitive credential disclosure, denial of service, remote code execution, or lateral movement depending on service account privileges and network environment.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Kofax Capture (Tungsten Capture)to a version that resolves this vulnerability.Fixed in 6.0.0.0 - Configuration
Restrict the deprecated .NET Remoting HTTP channel exposed by Ascent Capture Service on TCP port 2424 so it is no longer accessible without authentication (disable the unauthenticated access path or require authentication) and remove reliance on the default, publicly known endpoint identifier.
Kofax Capture (Tungsten Capture) - Ascent Capture Service (.NET Remoting HTTP channel) Authentication requirement for .NET Remoting HTTP channel on port 2424 = required - Compensating control
Block network access to Kofax Capture Ascent Capture Service TCP port 2424 at the firewall/ACL so unauthenticated remote attackers cannot reach the deprecated .NET Remoting HTTP channel.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23751?
CVE-2026-23751 is considered a high severity vulnerability due to its unauthenticated access and exposure of a deprecated .NET Remoting HTTP channel.
How do I fix CVE-2026-23751?
To fix CVE-2026-23751, it is recommended to disable the deprecated .NET Remoting HTTP channel or apply available patches from the vendor.
What systems are affected by CVE-2026-23751?
CVE-2026-23751 affects Kofax Capture (Tungsten Capture) version 6.0.0.0, with other versions potentially vulnerable.
What type of attack can exploit CVE-2026-23751?
CVE-2026-23751 can be exploited through unauthenticated access to the Ascent Capture Service, allowing unauthorized access to sensitive data.
Is there a known exploit for CVE-2026-23751?
Yes, there is known exploitation behavior associated with CVE-2026-23751, facilitating unauthorized operations via its exposed service.