VMware Alert: Uninstall EAP Now - Critical Flaw Puts Active Directory at Risk
ID: 47bce919-1ba2-5399-a344-a994925d0b91
STIX ID: report--47bce919-1ba2-5399-a344-a994925d0b91
Feed Name: The Hacker News
VMware has urged users to uninstall the deprecated Enhanced Authentication Plugin after disclosure of CVE-2024-22245 (CVSS 9.6) — an arbitrary authentication relay — and CVE-2024-22250 (CVSS 7.8) — a session hijack via local access; the flaws affect Windows systems with EAP installed and VMware recommends removal instead of issuing patches. The report also notes separate security issues: Joomla XSS vulnerabilities (CVE-2024-21726) addressed in recent releases and insecure Apex 'without sharing' usage in Salesforce that can lead to data leakage or corruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
