External risk intelligence

Entrust IFI Legacy Remoting Unauthenticated Network File Access and Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-34414

The vulnerability affects a specialized financial card issuance application. While the service is network-reachable and enabled by default, this software is typically deployed within controlled, internal financial processing environments rather than being exposed directly to the public internet. Public internet exposure is uncommon for this specific type of infrastructure.

Missing Authentication

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in Entrust Instant Financial Issuance On Premise software that could allow an unauthenticated attacker to access sensitive data or execute code on the affected server. This exposure stems from an insecure .NET Remoting service that is enabled by default and exposes certain functions. While the potential impact is significant, the primary concern for leadership is to confirm if this specific financial issuance software is in use within the organization and if it is exposed to any unauthorized access.

  • Unauthenticated remote access to sensitive data.
  • Confirm relevance and exposure for this financial software.
  • Assess business impact if this software is deployed.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable software over the network and interact with its exposed remoting service without any authentication. This allows them to invoke specific objects that can lead to the disclosure of sensitive system information, the ability to write arbitrary files on the server, or even execute code remotely, ultimately compromising the host system.

  • Unauthenticated network access required.
  • Invokes exposed remoting objects.
  • Arbitrary file write and code execution.

Live Threat

Current exploitation, exposure, and threat context

Entrust Instant Financial Issuance (IFI) On Premise software, when its Legacy Remoting Service is network-reachable and unauthenticated, could expose sensitive installation and service-account data. This could lead to the compromise of the affected host through known .NET Remoting exploitation techniques.

  • Server installation and service account data at risk.
  • Remote unauthenticated access to exposed objects.
  • Sensitive data disclosure and host compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

System owners and infrastructure teams are likely responsible for addressing this critical .NET Remoting exposure in Entrust IFI On Premise software. The first practical move is to identify all instances of the affected software, confirm their network reachability and business criticality, and then engage the accountable owner to plan remediation, which may involve vendor coordination or temporary risk reduction measures.

  • Ownership lies with system and infrastructure teams.
  • Verify network reachability and business criticality first.
  • Plan remediation with vendor coordination and risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Entrust Instant Financial Issuance (IFI) software?

Entrust IFI, previously known as CardWizard, is specialized on-premises software used by financial institutions and organizations to securely issue debit, credit, and other financial cards. It manages the workflows, data, and hardware communication necessary for printing and activating physical cards. Because it handles sensitive financial data and system credentials, it is typically deployed within highly controlled, internal processing environments rather than being accessible to the public.

What does CWE-502 and CWE-306 mean for CVE-2025-34414?

These codes represent common security weaknesses found in software. CWE-306 refers to missing authentication for critical functions, meaning the system allows commands to run without verifying who is asking. CWE-502 relates to insecure deserialization, where the software trusts incoming data too much when processing it. In this CVE, these flaws combine to let an unauthenticated user interact with the Legacy Remoting Service, effectively bypassing security controls to gain unauthorized control over the server.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending network traffic to the specific remoting port where the Legacy Remoting Service is active. Because this service is enabled by default and lacks authentication, the attacker can directly invoke exposed endpoints—such as file-related remoting objects—to perform unauthorized actions. Simply reaching the network port is the prerequisite; internal actions like logging into the application or using a user interface are not required to exploit this flaw.

Is my organization at risk if this software is internal?

While the vulnerability is severe, Halo Surface Signal notes that Entrust IFI is typically deployed in controlled, internal environments rather than the public internet. This makes direct, global exploitation less common. However, the risk remains if an attacker has already gained a foothold on your internal network, as they could then reach the vulnerable service from within your own infrastructure. You should prioritize servers that have broader network access.

What are the first steps to address this CVE?

Start by conducting an inventory to locate every instance of Entrust IFI On Premise within your environment. Once identified, evaluate the network placement of these servers to determine how reachable they are to unauthorized users. Consult the vendor's official guidance to confirm the specific version you are running and coordinate with your infrastructure team to implement necessary security updates or configuration changes to disable the insecure service.

References