Critical vulnerability in legacy remote VMware EAP. Remediate immediately.

VMware urges customers to remove legacy Enhanced Authentication Plugin (EAP) after disclosure of critical CVE-2024-22245 vulnerability. VMware is urging customers to remove the legacy Enhanced Authentication Plugin (EAP) following the discovery of arbitrary authentication vulnerability CVE-2024-22245 (CVSS score: 9.6).
An attacker can trick a domain user with an EAP installed in a web browser into requesting and transmitting service tickets for arbitrary Active Directory Service Principal Names (SPNs). A statement released by the leading virtualization giant said, "A common confirmation relay and session hijacking vulnerabilities in VMware's legacy Extended Authentication Plugin (EAP) have been reported to VMware."
According to the document, there is no workaround for this vulnerability.
The company also addressed the presence of an EAP session hijacking vulnerability categorized as important and identified as CVE-2024-22250 (CVSS score of 7.8). "An attacker with limited local access privileges to a Windows operating system can hijack a privileged EAP session if it is initiated by a privileged domain user on the same system," it said.
Both vulnerabilities were discovered by Ceri Coburn of Pen Test Partners.
Tags
We will find property for you
- 🔸 Reliable new buildings and ready-made apartments
- 🔸 Without commissions and intermediaries
- 🔸 Online display and remote transaction
International Real Estate Consultant
Subscribe to the newsletter from Hatamatata.com!
Subscribe to the newsletter from Hatamatata.com!
Popular Posts
We will find property for you
- 🔸 Reliable new buildings and ready-made apartments
- 🔸 Without commissions and intermediaries
- 🔸 Online display and remote transaction
International Real Estate Consultant
Subscribe to the newsletter from Hatamatata.com!
Subscribe to the newsletter from Hatamatata.com!
I agree to the processing of personal data and confidentiality rules of HatamatataNeed advice on your situation?
Get a free consultation on purchasing real estate overseas. We’ll discuss your goals, suggest the best strategies and countries, and explain how to complete the purchase step by step. You’ll get clear answers to all your questions about buying, investing, and relocating abroad.
Irina Nikolaeva
Sales Director, HataMatata