logo

No fix KrbRelay VMware style

ID: e2055396-8413-5041-976f-59200c3ba5ac

STIX ID: report--e2055396-8413-5041-976f-59200c3ba5ac

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-02-21

Date Updated: 2026-03-24

Author: Ceri Coburn

...
...

This report discloses two critical issues in VMware’s Enhanced Authentication Plugin for vSphere: CVE-2024-22245, enabling Kerberos relay via a browser-exposed plugin/WebSocket interface that a malicious website can abuse to request arbitrary service tickets; and CVE-2024-22250, allowing local session hijacking by reading session IDs from world-readable logs to obtain Kerberos tickets for other users. These flaws can be used to authenticate to AD-integrated services, including Azure Seamless SSO, without on-premises line-of-sight. VMware will not patch the deprecated plugin despite vSphere 7 support continuing until 2025; the recommended mitigation is to uninstall the plugin from all endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.