VMware urges admins to remove deprecated, vulnerable auth plug-in
ID: 737b009c-39ed-570f-be32-de8dfddc996f
STIX ID: report--737b009c-39ed-570f-be32-de8dfddc996f
Feed Name: Bleeping Computer
Threat Score
VMware has warned administrators to remove the deprecated VMware Enhanced Authentication Plug-in after two vulnerabilities (CVE-2024-22245, CVE-2024-22250) were disclosed that can enable Kerberos service ticket relaying and privileged session hijacking; VMware provides PowerShell commands to uninstall or disable the plugin/service, recommends alternative authentication methods, and states there is currently no evidence of in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
