VMWare Urges Users to Uninstall EAP Immediately

VMWare Urges Users to Uninstall EAP Immediately

VMware has issued a no-patch advisory urging users to take swift action by removing the deprecated Enhanced Authentication Plug-in (EAP). EAP was deprecated nearly three years ago, in March 2021, with the rollout of vCenter Server 7.0 Update 2. However, the discovery of an arbitrary authentication relay flaw in EAP, identified as CVE-2024-22245 with a … Read more

VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk

VMware Alert: Uninstall EAP Now – Critical Flaw Puts Active Directory at Risk

Feb 21, 2024NewsroomActive Directory / Vulnerability VMware is urging users to uninstall the deprecated Enhanced Authentication Plugin (EAP) following the discovery of a critical security flaw. Tracked as CVE-2024-22245 (CVSS score: 9.6), the vulnerability has been described as an arbitrary authentication relay bug. “A malicious actor could trick a target domain user with EAP installed … Read more

Critical flaw found in deprecated VMware EAP. Uninstall it now

Critical flaw found in deprecated VMware EAP. Uninstall it now

Critical flaw found in deprecated VMware EAP. Uninstall it immediately Pierluigi Paganini February 21, 2024 VMware urges customers to uninstall the deprecated Enhanced Authentication Plugin (EAP) after the disclosure of a critical flaw CVE-2024-22245. VMware is urging users to uninstall the deprecated Enhanced Authentication Plugin (EAP) after the discovery of an arbitrary authentication relay flaw … Read more