NA

CVE-2024-22245

Published: 20/02/2024 Updated: 17/05/2024

Vulnerability Summary

Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).

Vulnerability Trend

Recent Articles

VMware urges admins to remove deprecated, vulnerable auth plug-in
BleepingComputer • Sergiu Gatlan • 20 Feb 2024

VMware urges admins to remove deprecated, vulnerable auth plug-in By Sergiu Gatlan February 20, 2024 04:00 PM 0 VMware urged admins today to remove a discontinued authentication plugin exposed to authentication relay and session hijack attacks in Windows domain environments via two security vulnerabilities left unpatched. The vulnerable VMware Enhanced Authentication Plug-in (EAP) enables seamless login to vSphere's management interfaces via integrated Windows Authentication and Windows-bas...