QID 379396
Date Published: 2024-02-22
QID 379396: VMware Enhanced Authentication Plug-in (EAP) Multiple Security Vulnerabilities (VMSA-2024-0003)
The VMware Enhanced Authentication Plug-in provides Integrated Windows Authentication and Windows-based smart card functionality.
Arbitrary Authentication Relay Vulnerability in Deprecated EAP Browser Plugin (CVE-2024-22245)
Session Hijack Vulnerability in Deprecated EAP Browser Plugin (CVE-2024-22250)
Affected Versions:
VMware Enhanced Authentication Plug-in All Versions till 6.7.0
QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of VMware Enhanced Authentication Plug-in 6.7.0 by checking the windows registry.
A malicious actor could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).
A malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.
- VMSA-2024-0003 -
www.vmware.com/security/advisories/VMSA-2024-0003.html
CVEs related to QID 379396
| Advisory ID | Software | Component | Link |
|---|