PT-2024-1777 · Vmware · Vmware Enhanced Authentication Plug-In
Ceri Coburn
·
Published
2024-02-20
·
Updated
2024-11-01
·
CVE-2024-22245
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware Enhanced Authentication Plug-in (EAP) (affected versions not specified)
Description
The issue is related to arbitrary authentication relay and session hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP). This could allow a malicious actor to trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs). The estimated number of potentially affected devices worldwide is over 312,700 services.
Recommendations
Uninstall the deprecated Enhanced Authentication Plugin (EAP) from affected systems.
As a temporary workaround, consider restricting access to the EAP plugin until it is uninstalled.
Avoid using the EAP plugin for authentication until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vmware Enhanced Authentication Plug-In