CVE-2024-22245
CVE-2024-22245 is an authentication relay and session hijack vulnerability in the deprecated VMware Enhanced Authentication Plug-in (EAP). This flaw allows a malicious actor to deceive a user with EAP installed, causing them to request and relay service tickets for arbitrary Active Directory Service Principal Names (SPNs). Although the CVSS score is 0, meaning there's no base score calculation, the SOCRadar Vulnerability Risk Score (SVRS) of 34, combined with the "In The Wild" tag, indicates that the vulnerability is being actively exploited and should not be ignored. Successful exploitation could grant unauthorized access and control within the Active Directory environment. The vulnerability lies in the deprecated VMware EAP, suggesting that affected users should migrate away from it, even if the SVRS is not critically high, because active exploitation is occurring. Given the potential for session hijack, it is imperative that organizations review their systems for the presence of the deprecated EAP and prioritize remediation or removal to mitigate risks.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.