PT-2024-1777 · Vmware · Vmware Enhanced Authentication Plug-In

Ceri Coburn

·

Published

2024-02-20

·

Updated

2024-11-01

·

CVE-2024-22245

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware Enhanced Authentication Plug-in (EAP) (affected versions not specified)
Description The issue is related to arbitrary authentication relay and session hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP). This could allow a malicious actor to trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs). The estimated number of potentially affected devices worldwide is over 312,700 services.
Recommendations Uninstall the deprecated Enhanced Authentication Plugin (EAP) from affected systems. As a temporary workaround, consider restricting access to the EAP plugin until it is uninstalled. Avoid using the EAP plugin for authentication until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-01508
CVE-2024-22245

Affected Products

Vmware Enhanced Authentication Plug-In