NA

CVE-2024-22250

Published: 20/02/2024 Updated: 17/05/2024

Vulnerability Summary

Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.

Vulnerability Trend

Recent Articles

VMware urges admins to remove deprecated, vulnerable auth plug-in
BleepingComputer • Sergiu Gatlan • 20 Feb 2024

VMware urges admins to remove deprecated, vulnerable auth plug-in By Sergiu Gatlan February 20, 2024 04:00 PM 0 VMware urged admins today to remove a discontinued authentication plugin exposed to authentication relay and session hijack attacks in Windows domain environments via two security vulnerabilities left unpatched. The vulnerable VMware Enhanced Authentication Plug-in (EAP) enables seamless login to vSphere's management interfaces via integrated Windows Authentication and Windows-bas...