Open Nav
Sign Up

Security Flaw in VMware’s Enhanced Authentication Plugin (EAP) Puts Active Directory at Risk

Bar Refael

February 21, 2024

VMware has issued an urgent advisory to uninstall the deprecated Enhanced Authentication Plugin (EAP) due to a critical security flaw identified as CVE-2024-22245 (CVSS score: 9.6). The vulnerability is an arbitrary authentication relay bug that could compromise Active Directory.

Vulnerability Details:

  • CVE ID: CVE-2024-22245
  • CVSS Score: 9.6 (Critical)
  • Affected Software: VMware Enhanced Authentication Plugin (EAP)
  • Impact: Arbitrary authentication relay, compromising Active Directory

Description:

The vulnerability allows a malicious actor to trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs). EAP, deprecated as of March 2021, is designed for direct login to vSphere’s management interfaces and tools through a web browser. A related session hijack flaw (CVE-2024-22250, CVSS score: 7.8) was also discovered, allowing a malicious actor with unprivileged local access to a Windows operating system to seize a privileged EAP session.

Mitigation Strategies:

  • Uninstall EAP: VMware recommends uninstalling the Enhanced Authentication Plugin altogether to mitigate potential threats. Use the client operating system’s method of uninstalling software to remove EAP from client systems.
  • Monitor for Suspicious Activity: Keep an eye on Active Directory logs for any unusual activity that may indicate exploitation attempts.
  • Regular Updates: Ensure that all VMware and other software are up to date with the latest security patches and updates.

Recommendations:

IT and security teams should take immediate action to uninstall the Enhanced Authentication Plugin from affected systems. Given the critical nature of the vulnerability and its potential impact on Active Directory, swift remediation is essential to maintain the security of the network and sensitive data.

Stay safe and informed,

OP Innovate Research Team.

Resources highlights

Cisco SD-WAN Manager Zero-Day CVE-2026-76504 Exploited for Admin Access

Cisco has released emergency security updates for a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager, formerly known as vManage. Tracked as CVE-2026-76504, the…

Read more >

cisco sd-wan_cve-2026-76504

Two Citrix NetScaler RCE Zero-Days Exploited in the Wild: CVE-2026-88771 & CVE-2026-88772

Two critical zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway are being actively exploited to compromise vulnerable appliances. Tracked as CVE-2026-88771 and CVE-2026-88772, both…

Read more >

citrix netscaler_cve-2026-88771-88772

Critical cPanel Flaw CVE-2026-87899 Enables Root Code Execution

A critical vulnerability in cPanel & WHM can allow an authenticated cPanel user to escalate privileges and execute arbitrary code as the root user, potentially…

Read more >

cpanel_cve-2026-87899

WordPress Click2Shell Chains Forced Theme Installation to Remote Code Execution

A newly disclosed WordPress vulnerability chain dubbed Click2Shell can allow an unauthenticated attacker to turn a single malicious link opened by a logged-in WordPress administrator…

Read more >

wordpress click2shell

Cisco ISE Zero-Day CVE-2026-76460 Exploited for Authentication Bypass and Root Access

Cisco has disclosed a maximum-severity vulnerability in Cisco Identity Services Engine (ISE) that is being actively exploited in the wild. Tracked as CVE-2026-76460, the vulnerability…

Read more >

cisco ise_cve-2026-76460

Critical Check Point VPN RCE Flaws CVE-2026-85102 and CVE-2026-85103 Face Imminent Exploitation Risk

Check Point has released security updates for two critical vulnerabilities affecting its VPN infrastructure that could allow unauthenticated remote attackers to execute arbitrary code on…

Read more >

check point_cve-2026-85102-cve-2026-85103
Under Cyber Attack?

Fill out the form and we will contact you immediately.