VMware Alert: Uninstall EAP Now Critical flaws endanger Active Directory

February 21, 2024
1 min read




Article Summary

TLDR:

  • VMware is urging users to uninstall the deprecated Enhanced Authentication Plugin (EAP) due to a critical security flaw.
  • The flaw, CVE-2024-22245, allows arbitrary authentication relay, putting Active Directory at risk.

VMware has discovered a critical security flaw in the deprecated Enhanced Authentication Plugin (EAP), tracked as CVE-2024-22245 with a CVSS score of 9.6. The vulnerability allows for arbitrary authentication relay, posing a risk to Active Directory. EAP, which has been deprecated since March 2021, is a software package used for direct login to vSphere’s management interfaces through a web browser. Additionally, a session hijack flaw (CVE-2024-22250, CVSS score: 7.8) was also found in the EAP tool. Users are advised to remove the plugin to mitigate potential threats. Alongside this, SonarSource disclosed cross-site scripting flaws in Joomla! and vulnerabilities in the Apex programming language developed by Salesforce. These vulnerabilities underline the importance of software security and timely updates.


Latest from Blog

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives

Cyber insurance changes shape of security for good and bad

TLDR: Key Points: Cyber-insurance landscape is shifting to encourage greater cyber resiliency Rising costs of cyberattacks are prompting insurers to re-examine underwriting How Cyber-Insurance Shifts Affect the Security Landscape The article discusses