logo

Critical Vulnerability in VMware vSphere Plug-in Allows Session Hijacking

ID: 954e3937-2c4b-5055-b282-eee3e327c576

STIX ID: report--954e3937-2c4b-5055-b282-eee3e327c576

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-02-21

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

VMware warns administrators to remove the deprecated Enhanced Authentication Plug-in (EAP) after disclosure of two vulnerabilities—CVE-2024-22245 (critical Kerberos relay allowing authentication ticket relaying) and CVE-2024-22250 (session-hijack via weak log-file permissions)—that could let an attacker with local or web-based interaction hijack privileged vSphere sessions; VMware provides removal steps and recommends alternative authentication methods, and there is no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.