QID 379396

Date Published: 2024-02-22

QID 379396: VMware Enhanced Authentication Plug-in (EAP) Multiple Security Vulnerabilities (VMSA-2024-0003)

The VMware Enhanced Authentication Plug-in provides Integrated Windows Authentication and Windows-based smart card functionality.
Arbitrary Authentication Relay Vulnerability in Deprecated EAP Browser Plugin (CVE-2024-22245)
Session Hijack Vulnerability in Deprecated EAP Browser Plugin (CVE-2024-22250)
Affected Versions:
VMware Enhanced Authentication Plug-in All Versions till 6.7.0

QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of VMware Enhanced Authentication Plug-in 6.7.0 by checking the windows registry.

A malicious actor could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).
A malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.

  • CVSS V3 rated as Critical - 9.6 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    For more information please refer to KB96442

    CVEs related to QID 379396

    Software Advisories
    Advisory ID Software Component Link