logo

VMware Alert: Uninstall EAP Now - Critical Flaw Puts Active Directory at Risk

ID: 47bce919-1ba2-5399-a344-a994925d0b91

STIX ID: report--47bce919-1ba2-5399-a344-a994925d0b91

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-02-21

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

VMware has urged users to uninstall the deprecated Enhanced Authentication Plugin after disclosure of CVE-2024-22245 (CVSS 9.6) — an arbitrary authentication relay — and CVE-2024-22250 (CVSS 7.8) — a session hijack via local access; the flaws affect Windows systems with EAP installed and VMware recommends removal instead of issuing patches. The report also notes separate security issues: Joomla XSS vulnerabilities (CVE-2024-21726) addressed in recent releases and insecure Apex 'without sharing' usage in Salesforce that can lead to data leakage or corruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.