CVE-2024-22250: VMware Enhanced Authentication Plugin

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP session when initiated by a privileged domain user on the same system.

Affected products

  • VMware Enhanced Authentication Plugin: before 6.7.0 (fixed in 6.7.0)
  • VMware VMware Enhanced Authentication Plug-In Eap: any version

Published 2024-02-20. Last modified 2026-06-17.