CVE-2024-22245

CVSS V2 None CVSS V3 None
Description
Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).
Overview
  • CVE ID
  • CVE-2024-22245
  • Assigner
  • vmware
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-20T17:35:09.051Z
  • Last Modified Date
  • 2024-02-20T17:35:09.051Z
References
History
Created Old Value New Value Data Type Notes
2024-06-26 09:13:49 Added to TrackCVE