HomeSecurityVMware: Recommends removal of EAP plugin due to vulnerabilities

VMware: Recommends removal of EAP plugin due to vulnerabilities

VMware is urging administrators to remove an authentication pluginthat is vulnerable to relay and session hijack attacksdue to two vulnerabilities. The VMware Enhanced Authentication Plug-in (EAP) enables seamless login to vSphere management interfaces through Integrated Windows Authentication and Windows-based smart card functionality on Windows client systems.

VMware EAP authentication plugin vulnerabilities

VMware announced the removal of EAP in March 2021, with the release of vCenter Server 7.0 Update 2.

See also: 28,500 Exchange servers vulnerable to known vulnerability

The two vulnerabilities in the plugin are tracked as CVE-2024-22245 and CVE-2024-22250 and could allow attackers to relay Kerberos service tickets and take control of privileged EAP sessions.

“ A malicious actor could trick a domain user with EAP installed in their browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs) ,” VMware says about the CVE-2024-22245 vulnerability

"A malicious actor with unprivileged local access to a Windows operating system can compromise a privileged EAP session when initiated by a privileged domain user on the same system," the company said about CVE-2024-22250.

Ways of protection

Administrators are asked to remove the in-browser plugin/client (VMware Enhanced Authentication Plug-in 6.7.0) as well as the service Windows (VMware Plug-in Service).

See also: Hackers exploit vulnerability in Bricks Builder WordPress Theme

To uninstall them or disable the Windows service (if removal is not possible), it is useful to run the following PowerShell commands:

Uninstall ————————— (Get-WmiObject -Class Win32_Product | Where-Object{$_.Name.StartsWith("VMware Enhanced Authentication Plug-in")}).Uninstall() (Get-WmiObject -Class Win32_Product | Where-Object{$_.Name.StartsWith("VMware Plug-in Service")}).Uninstall() Stop/Disable service ——————————————————————— Stop-Service -Name "CipMsgProxyService" Set-Service -Name "CipMsgProxyService" -StartupType "Disabled"

The vulnerable VMware EAP is not installed by default and is not part of VMware's vCenter Server, ESXi, or Cloud Foundation products. So only those who have installed it manually are at risk

Instead of the vulnerable authentication plugin, VMware recommends other VMware vSphere 8 authentication methods, such as Active Directory via LDAPS, Microsoft Active Directory Federation Services (ADFS), Okta, and Microsoft Entra ID (formerly Azure AD).

See also: KeyTrap vulnerability: Interrupting internet access with DNS packet

VMware Enhanced Authentication Plug-in
VMware: Recommends removal of EAP plugin due to vulnerabilities

The reaction from the admin community is expected to be generally positive, with many recognizing the urgent need for action and removal of the vulnerable plugin.

However, there will certainly be some administrators who may be concerned about the potential consequences of removing the plugin, such as difficulty accessing and managing their systems. Despite these potential concerns, it is important to recognize the need to protect systems based on VMware's guidelines.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The protection of digital systems should be considered a priority, as it is critical to ensuring the integrity, confidentiality and availability of data and information. Without effective protection, digital systems are vulnerable to attacks that can cause serious damage.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS