logo

VMware urges admins to remove deprecated, vulnerable auth plug-in

ID: 737b009c-39ed-570f-be32-de8dfddc996f

STIX ID: report--737b009c-39ed-570f-be32-de8dfddc996f

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-02-20

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

VMware has warned administrators to remove the deprecated VMware Enhanced Authentication Plug-in after two vulnerabilities (CVE-2024-22245, CVE-2024-22250) were disclosed that can enable Kerberos service ticket relaying and privileged session hijacking; VMware provides PowerShell commands to uninstall or disable the plugin/service, recommends alternative authentication methods, and states there is currently no evidence of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.