← Back to CVE List

CVE-2024-22245

Published: 2024-02-20T18:15Z
Last Modified: 2024-11-21T08:55Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt