Critical Vulnerability in VMware vSphere Plug-in Allows Session Hijacking
ID: 954e3937-2c4b-5055-b282-eee3e327c576
STIX ID: report--954e3937-2c4b-5055-b282-eee3e327c576
Feed Name: Dark Reading
Date Published: 2024-02-21
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
VMware warns administrators to remove the deprecated Enhanced Authentication Plug-in (EAP) after disclosure of two vulnerabilities—CVE-2024-22245 (critical Kerberos relay allowing authentication ticket relaying) and CVE-2024-22250 (session-hijack via weak log-file permissions)—that could let an attacker with local or web-based interaction hijack privileged vSphere sessions; VMware provides removal steps and recommends alternative authentication methods, and there is no evidence of active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
