#VU86654 Permissions, Privileges, and Access Controls in Enhanced Authentication Plug-in (EAP) - CVE-2024-22250

 

#VU86654 Permissions, Privileges, and Access Controls in Enhanced Authentication Plug-in (EAP) - CVE-2024-22250

Published: February 20, 2024 / Updated: September 4, 2024


Vulnerability identifier: #VU86654
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-22250
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Enhanced Authentication Plug-in (EAP)
Software vendor:
VMware, Inc

Description

The vulnerability allows a local user to hijack victim's session.

The vulnerability exists due to the way EAP initiates and handles sessions with the AD. A local user can hijack a privileged EAP session when initiated by a privileged domain user on the same system.

Remediation

This plugin is no longer supported and will not receive any security updates. It is recommended to remove it from your systems.


External links